MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ffb79f36daa86e4b5ada078827f93024feb24cce891a1dfc6092ceaab990737. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 0ffb79f36daa86e4b5ada078827f93024feb24cce891a1dfc6092ceaab990737
SHA3-384 hash: b00f335239d77d346ce7ce24a38972a9569b0a3951d504f1991ff35ad2a3eb3e5cee7404b4badbab99b88df0c593292f
SHA1 hash: a323f42407b92713d2ca3e364b54852509faf56b
MD5 hash: 35327a0d41b9f2ae23822d4e757fb0c4
humanhash: tennessee-paris-football-asparagus
File name:p
Download: download sample
File size:839 bytes
First seen:2026-06-21 03:54:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaabJw/bXFvBG3whLTOcFvUC37:e9Qp+MsaS/jFQwhnOcF337
TLSH T1BE01AFDA8610A9100059A65E22975590B861C3CF059B0F787FAC0E3EFB98410B166F9D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/IKjcn/an/aelf ua-wget
http://129.121.114.124/ropdn/an/aelf ua-wget
http://129.121.114.124/V1un/an/aelf ua-wget
http://129.121.114.124/T0kcn/an/aelf ua-wget
http://129.121.114.124/Vmun/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=62dde18c-1a00-0000-658c-66ed3d0c0000 pid=3133 /usr/bin/sudo guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140 /tmp/sample.bin write-file guuid=62dde18c-1a00-0000-658c-66ed3d0c0000 pid=3133->guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140 execve guuid=de99c28f-1a00-0000-658c-66ed460c0000 pid=3142 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=de99c28f-1a00-0000-658c-66ed460c0000 pid=3142 execve guuid=2c5e8d90-1a00-0000-658c-66ed480c0000 pid=3144 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=2c5e8d90-1a00-0000-658c-66ed480c0000 pid=3144 execve guuid=abd7f890-1a00-0000-658c-66ed4b0c0000 pid=3147 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=abd7f890-1a00-0000-658c-66ed4b0c0000 pid=3147 execve guuid=96016e91-1a00-0000-658c-66ed4c0c0000 pid=3148 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=96016e91-1a00-0000-658c-66ed4c0c0000 pid=3148 execve guuid=c35fe991-1a00-0000-658c-66ed4e0c0000 pid=3150 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=c35fe991-1a00-0000-658c-66ed4e0c0000 pid=3150 execve guuid=96237492-1a00-0000-658c-66ed4f0c0000 pid=3151 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=96237492-1a00-0000-658c-66ed4f0c0000 pid=3151 execve guuid=35aefe92-1a00-0000-658c-66ed500c0000 pid=3152 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=35aefe92-1a00-0000-658c-66ed500c0000 pid=3152 execve guuid=7259a793-1a00-0000-658c-66ed520c0000 pid=3154 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=7259a793-1a00-0000-658c-66ed520c0000 pid=3154 execve guuid=00175194-1a00-0000-658c-66ed540c0000 pid=3156 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=00175194-1a00-0000-658c-66ed540c0000 pid=3156 execve guuid=58632e95-1a00-0000-658c-66ed580c0000 pid=3160 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=58632e95-1a00-0000-658c-66ed580c0000 pid=3160 execve guuid=9939d895-1a00-0000-658c-66ed5a0c0000 pid=3162 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9939d895-1a00-0000-658c-66ed5a0c0000 pid=3162 execve guuid=b29e7396-1a00-0000-658c-66ed5b0c0000 pid=3163 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b29e7396-1a00-0000-658c-66ed5b0c0000 pid=3163 execve guuid=6a653997-1a00-0000-658c-66ed5d0c0000 pid=3165 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=6a653997-1a00-0000-658c-66ed5d0c0000 pid=3165 execve guuid=e40f2598-1a00-0000-658c-66ed5e0c0000 pid=3166 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e40f2598-1a00-0000-658c-66ed5e0c0000 pid=3166 execve guuid=3aaedf98-1a00-0000-658c-66ed5f0c0000 pid=3167 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=3aaedf98-1a00-0000-658c-66ed5f0c0000 pid=3167 execve guuid=bf237099-1a00-0000-658c-66ed620c0000 pid=3170 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=bf237099-1a00-0000-658c-66ed620c0000 pid=3170 execve guuid=6da5059a-1a00-0000-658c-66ed640c0000 pid=3172 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=6da5059a-1a00-0000-658c-66ed640c0000 pid=3172 execve guuid=9cc7929a-1a00-0000-658c-66ed660c0000 pid=3174 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9cc7929a-1a00-0000-658c-66ed660c0000 pid=3174 execve guuid=5e800a9b-1a00-0000-658c-66ed690c0000 pid=3177 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=5e800a9b-1a00-0000-658c-66ed690c0000 pid=3177 execve guuid=c4958f9b-1a00-0000-658c-66ed6b0c0000 pid=3179 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=c4958f9b-1a00-0000-658c-66ed6b0c0000 pid=3179 execve guuid=b1390e9c-1a00-0000-658c-66ed6e0c0000 pid=3182 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b1390e9c-1a00-0000-658c-66ed6e0c0000 pid=3182 execve guuid=9347749c-1a00-0000-658c-66ed700c0000 pid=3184 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9347749c-1a00-0000-658c-66ed700c0000 pid=3184 execve guuid=e327f09c-1a00-0000-658c-66ed710c0000 pid=3185 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e327f09c-1a00-0000-658c-66ed710c0000 pid=3185 execve guuid=16ef7c9d-1a00-0000-658c-66ed720c0000 pid=3186 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=16ef7c9d-1a00-0000-658c-66ed720c0000 pid=3186 execve guuid=8e73159e-1a00-0000-658c-66ed730c0000 pid=3187 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=8e73159e-1a00-0000-658c-66ed730c0000 pid=3187 execve guuid=82d2959e-1a00-0000-658c-66ed740c0000 pid=3188 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=82d2959e-1a00-0000-658c-66ed740c0000 pid=3188 execve guuid=f8185b9f-1a00-0000-658c-66ed750c0000 pid=3189 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=f8185b9f-1a00-0000-658c-66ed750c0000 pid=3189 execve guuid=eaa92ba0-1a00-0000-658c-66ed760c0000 pid=3190 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=eaa92ba0-1a00-0000-658c-66ed760c0000 pid=3190 execve guuid=446fc5a0-1a00-0000-658c-66ed770c0000 pid=3191 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=446fc5a0-1a00-0000-658c-66ed770c0000 pid=3191 execve guuid=b01d7aa1-1a00-0000-658c-66ed780c0000 pid=3192 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b01d7aa1-1a00-0000-658c-66ed780c0000 pid=3192 execve guuid=98e009a2-1a00-0000-658c-66ed790c0000 pid=3193 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=98e009a2-1a00-0000-658c-66ed790c0000 pid=3193 execve guuid=bfc9baa2-1a00-0000-658c-66ed7a0c0000 pid=3194 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=bfc9baa2-1a00-0000-658c-66ed7a0c0000 pid=3194 execve guuid=b99f5fa3-1a00-0000-658c-66ed7b0c0000 pid=3195 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b99f5fa3-1a00-0000-658c-66ed7b0c0000 pid=3195 execve guuid=bbc608a4-1a00-0000-658c-66ed7c0c0000 pid=3196 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=bbc608a4-1a00-0000-658c-66ed7c0c0000 pid=3196 execve guuid=3955a9a4-1a00-0000-658c-66ed7d0c0000 pid=3197 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=3955a9a4-1a00-0000-658c-66ed7d0c0000 pid=3197 execve guuid=cfed7aa5-1a00-0000-658c-66ed7e0c0000 pid=3198 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=cfed7aa5-1a00-0000-658c-66ed7e0c0000 pid=3198 execve guuid=4fb119a6-1a00-0000-658c-66ed7f0c0000 pid=3199 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=4fb119a6-1a00-0000-658c-66ed7f0c0000 pid=3199 execve guuid=e22bbea6-1a00-0000-658c-66ed800c0000 pid=3200 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e22bbea6-1a00-0000-658c-66ed800c0000 pid=3200 execve guuid=059167a7-1a00-0000-658c-66ed810c0000 pid=3201 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=059167a7-1a00-0000-658c-66ed810c0000 pid=3201 execve guuid=1391fca7-1a00-0000-658c-66ed820c0000 pid=3202 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=1391fca7-1a00-0000-658c-66ed820c0000 pid=3202 execve guuid=ba8fc0a8-1a00-0000-658c-66ed830c0000 pid=3203 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ba8fc0a8-1a00-0000-658c-66ed830c0000 pid=3203 execve guuid=328587a9-1a00-0000-658c-66ed840c0000 pid=3204 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=328587a9-1a00-0000-658c-66ed840c0000 pid=3204 execve guuid=863b1caa-1a00-0000-658c-66ed850c0000 pid=3205 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=863b1caa-1a00-0000-658c-66ed850c0000 pid=3205 execve guuid=c8b1dbaa-1a00-0000-658c-66ed860c0000 pid=3206 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=c8b1dbaa-1a00-0000-658c-66ed860c0000 pid=3206 execve guuid=b8a5a4ab-1a00-0000-658c-66ed870c0000 pid=3207 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b8a5a4ab-1a00-0000-658c-66ed870c0000 pid=3207 execve guuid=1b2216ac-1a00-0000-658c-66ed880c0000 pid=3208 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=1b2216ac-1a00-0000-658c-66ed880c0000 pid=3208 execve guuid=60f3ccac-1a00-0000-658c-66ed890c0000 pid=3209 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=60f3ccac-1a00-0000-658c-66ed890c0000 pid=3209 execve guuid=9e6f6fad-1a00-0000-658c-66ed8a0c0000 pid=3210 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9e6f6fad-1a00-0000-658c-66ed8a0c0000 pid=3210 execve guuid=ceb3eaad-1a00-0000-658c-66ed8b0c0000 pid=3211 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ceb3eaad-1a00-0000-658c-66ed8b0c0000 pid=3211 execve guuid=58a4b4ae-1a00-0000-658c-66ed8c0c0000 pid=3212 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=58a4b4ae-1a00-0000-658c-66ed8c0c0000 pid=3212 execve guuid=ce8f79af-1a00-0000-658c-66ed8d0c0000 pid=3213 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ce8f79af-1a00-0000-658c-66ed8d0c0000 pid=3213 execve guuid=e6bf58b0-1a00-0000-658c-66ed8e0c0000 pid=3214 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e6bf58b0-1a00-0000-658c-66ed8e0c0000 pid=3214 execve guuid=795931b1-1a00-0000-658c-66ed8f0c0000 pid=3215 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=795931b1-1a00-0000-658c-66ed8f0c0000 pid=3215 execve guuid=a9e2edb1-1a00-0000-658c-66ed900c0000 pid=3216 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=a9e2edb1-1a00-0000-658c-66ed900c0000 pid=3216 execve guuid=15eab9b2-1a00-0000-658c-66ed910c0000 pid=3217 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=15eab9b2-1a00-0000-658c-66ed910c0000 pid=3217 execve guuid=2a8e51b3-1a00-0000-658c-66ed920c0000 pid=3218 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=2a8e51b3-1a00-0000-658c-66ed920c0000 pid=3218 execve guuid=7da7f9b3-1a00-0000-658c-66ed930c0000 pid=3219 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=7da7f9b3-1a00-0000-658c-66ed930c0000 pid=3219 execve guuid=938dc2b4-1a00-0000-658c-66ed940c0000 pid=3220 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=938dc2b4-1a00-0000-658c-66ed940c0000 pid=3220 execve guuid=7e59e5b5-1a00-0000-658c-66ed960c0000 pid=3222 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=7e59e5b5-1a00-0000-658c-66ed960c0000 pid=3222 execve guuid=ac206bb6-1a00-0000-658c-66ed970c0000 pid=3223 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ac206bb6-1a00-0000-658c-66ed970c0000 pid=3223 execve guuid=6b62e2b6-1a00-0000-658c-66ed980c0000 pid=3224 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=6b62e2b6-1a00-0000-658c-66ed980c0000 pid=3224 execve guuid=421e5ab7-1a00-0000-658c-66ed990c0000 pid=3225 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=421e5ab7-1a00-0000-658c-66ed990c0000 pid=3225 execve guuid=88e0d9b7-1a00-0000-658c-66ed9b0c0000 pid=3227 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=88e0d9b7-1a00-0000-658c-66ed9b0c0000 pid=3227 execve guuid=fb593ab8-1a00-0000-658c-66ed9d0c0000 pid=3229 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=fb593ab8-1a00-0000-658c-66ed9d0c0000 pid=3229 execve guuid=ef360eb9-1a00-0000-658c-66eda00c0000 pid=3232 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ef360eb9-1a00-0000-658c-66eda00c0000 pid=3232 execve guuid=1b8376b9-1a00-0000-658c-66eda30c0000 pid=3235 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=1b8376b9-1a00-0000-658c-66eda30c0000 pid=3235 execve guuid=4ce9e3b9-1a00-0000-658c-66eda40c0000 pid=3236 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=4ce9e3b9-1a00-0000-658c-66eda40c0000 pid=3236 execve guuid=9d384fba-1a00-0000-658c-66eda60c0000 pid=3238 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9d384fba-1a00-0000-658c-66eda60c0000 pid=3238 execve guuid=56c7ccba-1a00-0000-658c-66eda70c0000 pid=3239 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=56c7ccba-1a00-0000-658c-66eda70c0000 pid=3239 execve guuid=e1026fbb-1a00-0000-658c-66eda90c0000 pid=3241 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e1026fbb-1a00-0000-658c-66eda90c0000 pid=3241 execve guuid=fdc10abc-1a00-0000-658c-66edac0c0000 pid=3244 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=fdc10abc-1a00-0000-658c-66edac0c0000 pid=3244 execve guuid=0f7f9ebc-1a00-0000-658c-66edae0c0000 pid=3246 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=0f7f9ebc-1a00-0000-658c-66edae0c0000 pid=3246 execve guuid=ee5a31bd-1a00-0000-658c-66edb10c0000 pid=3249 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ee5a31bd-1a00-0000-658c-66edb10c0000 pid=3249 execve guuid=972f98bd-1a00-0000-658c-66edb20c0000 pid=3250 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=972f98bd-1a00-0000-658c-66edb20c0000 pid=3250 execve guuid=791d21be-1a00-0000-658c-66edb30c0000 pid=3251 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=791d21be-1a00-0000-658c-66edb30c0000 pid=3251 execve guuid=dfcee1be-1a00-0000-658c-66edb50c0000 pid=3253 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=dfcee1be-1a00-0000-658c-66edb50c0000 pid=3253 execve guuid=4d32c9bf-1a00-0000-658c-66edb60c0000 pid=3254 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=4d32c9bf-1a00-0000-658c-66edb60c0000 pid=3254 execve guuid=2a9044c0-1a00-0000-658c-66edb70c0000 pid=3255 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=2a9044c0-1a00-0000-658c-66edb70c0000 pid=3255 execve guuid=d0a1c2c0-1a00-0000-658c-66edb80c0000 pid=3256 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=d0a1c2c0-1a00-0000-658c-66edb80c0000 pid=3256 execve guuid=cd9ca9c1-1a00-0000-658c-66edbc0c0000 pid=3260 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=cd9ca9c1-1a00-0000-658c-66edbc0c0000 pid=3260 execve guuid=c6b325c2-1a00-0000-658c-66edbe0c0000 pid=3262 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=c6b325c2-1a00-0000-658c-66edbe0c0000 pid=3262 execve guuid=5d57b4c2-1a00-0000-658c-66edc00c0000 pid=3264 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=5d57b4c2-1a00-0000-658c-66edc00c0000 pid=3264 execve guuid=96172fc3-1a00-0000-658c-66edc20c0000 pid=3266 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=96172fc3-1a00-0000-658c-66edc20c0000 pid=3266 execve guuid=47f8d0c3-1a00-0000-658c-66edc30c0000 pid=3267 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=47f8d0c3-1a00-0000-658c-66edc30c0000 pid=3267 execve guuid=1d286dc4-1a00-0000-658c-66edc40c0000 pid=3268 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=1d286dc4-1a00-0000-658c-66edc40c0000 pid=3268 execve guuid=d52cf0c4-1a00-0000-658c-66edc50c0000 pid=3269 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=d52cf0c4-1a00-0000-658c-66edc50c0000 pid=3269 execve guuid=b0398cc5-1a00-0000-658c-66edc60c0000 pid=3270 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b0398cc5-1a00-0000-658c-66edc60c0000 pid=3270 execve guuid=14e04ac6-1a00-0000-658c-66edc70c0000 pid=3271 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=14e04ac6-1a00-0000-658c-66edc70c0000 pid=3271 execve guuid=cb84e7c6-1a00-0000-658c-66edc80c0000 pid=3272 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=cb84e7c6-1a00-0000-658c-66edc80c0000 pid=3272 execve guuid=326878c7-1a00-0000-658c-66edc90c0000 pid=3273 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=326878c7-1a00-0000-658c-66edc90c0000 pid=3273 execve guuid=60f614c8-1a00-0000-658c-66edca0c0000 pid=3274 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=60f614c8-1a00-0000-658c-66edca0c0000 pid=3274 execve guuid=b6f9bac8-1a00-0000-658c-66edcb0c0000 pid=3275 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b6f9bac8-1a00-0000-658c-66edcb0c0000 pid=3275 execve guuid=8ffd25c9-1a00-0000-658c-66edcc0c0000 pid=3276 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=8ffd25c9-1a00-0000-658c-66edcc0c0000 pid=3276 execve guuid=3fcfffc9-1a00-0000-658c-66edcd0c0000 pid=3277 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=3fcfffc9-1a00-0000-658c-66edcd0c0000 pid=3277 execve guuid=e51daaca-1a00-0000-658c-66edce0c0000 pid=3278 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e51daaca-1a00-0000-658c-66edce0c0000 pid=3278 execve guuid=ab5c8dcb-1a00-0000-658c-66edcf0c0000 pid=3279 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ab5c8dcb-1a00-0000-658c-66edcf0c0000 pid=3279 execve guuid=4b144fcc-1a00-0000-658c-66edd00c0000 pid=3280 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=4b144fcc-1a00-0000-658c-66edd00c0000 pid=3280 execve guuid=44fafdcc-1a00-0000-658c-66edd10c0000 pid=3281 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=44fafdcc-1a00-0000-658c-66edd10c0000 pid=3281 execve guuid=4cb2bdcd-1a00-0000-658c-66edd20c0000 pid=3282 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=4cb2bdcd-1a00-0000-658c-66edd20c0000 pid=3282 execve guuid=21207bce-1a00-0000-658c-66edd30c0000 pid=3283 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=21207bce-1a00-0000-658c-66edd30c0000 pid=3283 execve guuid=c1d704cf-1a00-0000-658c-66edd40c0000 pid=3284 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=c1d704cf-1a00-0000-658c-66edd40c0000 pid=3284 execve guuid=73f281cf-1a00-0000-658c-66edd50c0000 pid=3285 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=73f281cf-1a00-0000-658c-66edd50c0000 pid=3285 execve guuid=874702d0-1a00-0000-658c-66edd60c0000 pid=3286 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=874702d0-1a00-0000-658c-66edd60c0000 pid=3286 execve guuid=9ba182d0-1a00-0000-658c-66edd70c0000 pid=3287 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9ba182d0-1a00-0000-658c-66edd70c0000 pid=3287 execve guuid=e92f00d1-1a00-0000-658c-66edd80c0000 pid=3288 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e92f00d1-1a00-0000-658c-66edd80c0000 pid=3288 execve guuid=ec9b79d1-1a00-0000-658c-66edd90c0000 pid=3289 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ec9b79d1-1a00-0000-658c-66edd90c0000 pid=3289 execve guuid=aaefefd1-1a00-0000-658c-66eddb0c0000 pid=3291 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=aaefefd1-1a00-0000-658c-66eddb0c0000 pid=3291 execve guuid=b7dc69d2-1a00-0000-658c-66eddc0c0000 pid=3292 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=b7dc69d2-1a00-0000-658c-66eddc0c0000 pid=3292 execve guuid=57f7f1d2-1a00-0000-658c-66eddd0c0000 pid=3293 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=57f7f1d2-1a00-0000-658c-66eddd0c0000 pid=3293 execve guuid=ef31c7d3-1a00-0000-658c-66ede00c0000 pid=3296 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ef31c7d3-1a00-0000-658c-66ede00c0000 pid=3296 execve guuid=64622bd4-1a00-0000-658c-66ede20c0000 pid=3298 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=64622bd4-1a00-0000-658c-66ede20c0000 pid=3298 execve guuid=893e9ed4-1a00-0000-658c-66ede50c0000 pid=3301 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=893e9ed4-1a00-0000-658c-66ede50c0000 pid=3301 execve guuid=61e006d5-1a00-0000-658c-66ede70c0000 pid=3303 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=61e006d5-1a00-0000-658c-66ede70c0000 pid=3303 execve guuid=505c76d5-1a00-0000-658c-66ede90c0000 pid=3305 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=505c76d5-1a00-0000-658c-66ede90c0000 pid=3305 execve guuid=ed28fed5-1a00-0000-658c-66edea0c0000 pid=3306 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ed28fed5-1a00-0000-658c-66edea0c0000 pid=3306 execve guuid=7fda7cd6-1a00-0000-658c-66edeb0c0000 pid=3307 /usr/bin/ls guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=7fda7cd6-1a00-0000-658c-66edeb0c0000 pid=3307 execve guuid=5472f2d6-1a00-0000-658c-66eded0c0000 pid=3309 /usr/bin/rm guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=5472f2d6-1a00-0000-658c-66eded0c0000 pid=3309 execve guuid=c7eb2dd7-1a00-0000-658c-66edef0c0000 pid=3311 /usr/bin/wget net send-data write-file guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=c7eb2dd7-1a00-0000-658c-66edef0c0000 pid=3311 execve guuid=f72c08f1-1a00-0000-658c-66ed1b0d0000 pid=3355 /usr/bin/chmod guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=f72c08f1-1a00-0000-658c-66ed1b0d0000 pid=3355 execve guuid=5d536ff1-1a00-0000-658c-66ed1d0d0000 pid=3357 /usr/bin/dash guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=5d536ff1-1a00-0000-658c-66ed1d0d0000 pid=3357 clone guuid=1ea664f2-1a00-0000-658c-66ed220d0000 pid=3362 /usr/bin/rm guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=1ea664f2-1a00-0000-658c-66ed220d0000 pid=3362 execve guuid=fafba7f2-1a00-0000-658c-66ed240d0000 pid=3364 /usr/bin/wget net send-data write-file guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=fafba7f2-1a00-0000-658c-66ed240d0000 pid=3364 execve guuid=bc11d10c-1b00-0000-658c-66ed470d0000 pid=3399 /usr/bin/chmod guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=bc11d10c-1b00-0000-658c-66ed470d0000 pid=3399 execve guuid=ba6d690d-1b00-0000-658c-66ed480d0000 pid=3400 /usr/bin/dash guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=ba6d690d-1b00-0000-658c-66ed480d0000 pid=3400 clone guuid=fe705b0e-1b00-0000-658c-66ed4a0d0000 pid=3402 /usr/bin/rm guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=fe705b0e-1b00-0000-658c-66ed4a0d0000 pid=3402 execve guuid=a5a3e70e-1b00-0000-658c-66ed4b0d0000 pid=3403 /usr/bin/wget net send-data write-file guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=a5a3e70e-1b00-0000-658c-66ed4b0d0000 pid=3403 execve guuid=62300728-1b00-0000-658c-66ed670d0000 pid=3431 /usr/bin/chmod guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=62300728-1b00-0000-658c-66ed670d0000 pid=3431 execve guuid=8f425128-1b00-0000-658c-66ed690d0000 pid=3433 /usr/bin/dash guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=8f425128-1b00-0000-658c-66ed690d0000 pid=3433 clone guuid=23fde528-1b00-0000-658c-66ed6d0d0000 pid=3437 /usr/bin/rm guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=23fde528-1b00-0000-658c-66ed6d0d0000 pid=3437 execve guuid=e71e2229-1b00-0000-658c-66ed6f0d0000 pid=3439 /usr/bin/wget net send-data write-file guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=e71e2229-1b00-0000-658c-66ed6f0d0000 pid=3439 execve guuid=8f0ddf46-1b00-0000-658c-66edb40d0000 pid=3508 /usr/bin/chmod guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=8f0ddf46-1b00-0000-658c-66edb40d0000 pid=3508 execve guuid=2e163347-1b00-0000-658c-66edb50d0000 pid=3509 /usr/bin/dash guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=2e163347-1b00-0000-658c-66edb50d0000 pid=3509 clone guuid=9ff8ec47-1b00-0000-658c-66edb90d0000 pid=3513 /usr/bin/rm guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=9ff8ec47-1b00-0000-658c-66edb90d0000 pid=3513 execve guuid=5acd3a48-1b00-0000-658c-66edbb0d0000 pid=3515 /usr/bin/wget net send-data write-file guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=5acd3a48-1b00-0000-658c-66edbb0d0000 pid=3515 execve guuid=cb311c66-1b00-0000-658c-66edff0d0000 pid=3583 /usr/bin/chmod guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=cb311c66-1b00-0000-658c-66edff0d0000 pid=3583 execve guuid=58185866-1b00-0000-658c-66ed010e0000 pid=3585 /usr/bin/dash guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=58185866-1b00-0000-658c-66ed010e0000 pid=3585 clone guuid=6d91e766-1b00-0000-658c-66ed050e0000 pid=3589 /usr/bin/rm delete-file guuid=0200578f-1a00-0000-658c-66ed440c0000 pid=3140->guuid=6d91e766-1b00-0000-658c-66ed050e0000 pid=3589 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=c7eb2dd7-1a00-0000-658c-66edef0c0000 pid=3311->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=fafba7f2-1a00-0000-658c-66ed240d0000 pid=3364->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=a5a3e70e-1b00-0000-658c-66ed4b0d0000 pid=3403->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=e71e2229-1b00-0000-658c-66ed6f0d0000 pid=3439->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=5acd3a48-1b00-0000-658c-66edbb0d0000 pid=3515->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0ffb79f36daa86e4b5ada078827f93024feb24cce891a1dfc6092ceaab990737

(this sample)

  
Delivery method
Distributed via web download

Comments