MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11c6c1093456e9eb949778d8fa9987cc7ffbd678fa2d30268f6e6b2ac2a320fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 11c6c1093456e9eb949778d8fa9987cc7ffbd678fa2d30268f6e6b2ac2a320fb
SHA3-384 hash: d8ce8290dc1b17f757b27f3216fe96032ceecd734a62033664d8932eba33c02eda32f05ce65c97166be6fb58cce475b4
SHA1 hash: 791a6ff8f630ac0d1e91a68fb972a31d126866cd
MD5 hash: c4ac1b5aa602945c0e8d8c8148205137
humanhash: magazine-minnesota-venus-bravo
File name:curl.sh
Download: download sample
File size:1'449 bytes
First seen:2026-06-10 13:54:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ZBqglRB0G29BCmnBQs1gBDmMBdTCsCBp1k8dBLETB4bmfSVBz0bsFByU5vBDZUw:/jppsCmBJeDmAd+sCjk8DLYjfSrz4ayI
TLSH T1C9314BE4A1D01BF31ED4CE05BB2359BD60AC40CE7F2EA7D8A46908DD67957C3F188259
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.175.249.53/armn/an/aelf ua-wget
http://5.175.249.53/arm5n/an/aelf ua-wget
http://5.175.249.53/arm6n/an/aelf ua-wget
http://5.175.249.53/arm7n/an/aelf ua-wget
http://5.175.249.53/m68kn/an/aelf ua-wget
http://5.175.249.53/mipsn/an/aelf ua-wget
http://5.175.249.53/mpsln/an/aelf ua-wget
http://5.175.249.53/ppcn/an/aelf ua-wget
http://5.175.249.53/sh4n/an/aelf ua-wget
http://5.175.249.53/spcn/an/aelf ua-wget
http://5.175.249.53/x86n/an/aelf ua-wget
http://5.175.249.53/arcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-10T11:01:00Z UTC
Last seen:
2026-06-10T11:15:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.cx
Status:
terminated
Behavior Graph:
%3 guuid=bcc6e35f-1900-0000-4e4f-adf72d0a0000 pid=2605 /usr/bin/sudo guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611 /tmp/sample.bin guuid=bcc6e35f-1900-0000-4e4f-adf72d0a0000 pid=2605->guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611 execve guuid=2b3a3462-1900-0000-4e4f-adf7360a0000 pid=2614 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=2b3a3462-1900-0000-4e4f-adf7360a0000 pid=2614 execve guuid=cbeda062-1900-0000-4e4f-adf7380a0000 pid=2616 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=cbeda062-1900-0000-4e4f-adf7380a0000 pid=2616 execve guuid=2279c662-1900-0000-4e4f-adf7390a0000 pid=2617 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=2279c662-1900-0000-4e4f-adf7390a0000 pid=2617 clone guuid=7034cd62-1900-0000-4e4f-adf73b0a0000 pid=2619 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=7034cd62-1900-0000-4e4f-adf73b0a0000 pid=2619 execve guuid=627af062-1900-0000-4e4f-adf73c0a0000 pid=2620 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=627af062-1900-0000-4e4f-adf73c0a0000 pid=2620 execve guuid=8fa62663-1900-0000-4e4f-adf73e0a0000 pid=2622 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=8fa62663-1900-0000-4e4f-adf73e0a0000 pid=2622 execve guuid=89574f63-1900-0000-4e4f-adf73f0a0000 pid=2623 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=89574f63-1900-0000-4e4f-adf73f0a0000 pid=2623 clone guuid=f23c5463-1900-0000-4e4f-adf7410a0000 pid=2625 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=f23c5463-1900-0000-4e4f-adf7410a0000 pid=2625 execve guuid=a94e7c63-1900-0000-4e4f-adf7420a0000 pid=2626 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=a94e7c63-1900-0000-4e4f-adf7420a0000 pid=2626 execve guuid=5f559d63-1900-0000-4e4f-adf7440a0000 pid=2628 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=5f559d63-1900-0000-4e4f-adf7440a0000 pid=2628 execve guuid=0626be63-1900-0000-4e4f-adf7450a0000 pid=2629 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=0626be63-1900-0000-4e4f-adf7450a0000 pid=2629 clone guuid=05afc263-1900-0000-4e4f-adf7460a0000 pid=2630 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=05afc263-1900-0000-4e4f-adf7460a0000 pid=2630 execve guuid=91c2f963-1900-0000-4e4f-adf7470a0000 pid=2631 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=91c2f963-1900-0000-4e4f-adf7470a0000 pid=2631 execve guuid=2f721a64-1900-0000-4e4f-adf7490a0000 pid=2633 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=2f721a64-1900-0000-4e4f-adf7490a0000 pid=2633 execve guuid=0e1f3964-1900-0000-4e4f-adf74a0a0000 pid=2634 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=0e1f3964-1900-0000-4e4f-adf74a0a0000 pid=2634 clone guuid=b62c4464-1900-0000-4e4f-adf74b0a0000 pid=2635 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=b62c4464-1900-0000-4e4f-adf74b0a0000 pid=2635 execve guuid=745b6b64-1900-0000-4e4f-adf74d0a0000 pid=2637 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=745b6b64-1900-0000-4e4f-adf74d0a0000 pid=2637 execve guuid=eb36a164-1900-0000-4e4f-adf74f0a0000 pid=2639 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=eb36a164-1900-0000-4e4f-adf74f0a0000 pid=2639 execve guuid=4575c664-1900-0000-4e4f-adf7500a0000 pid=2640 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=4575c664-1900-0000-4e4f-adf7500a0000 pid=2640 clone guuid=d10fcd64-1900-0000-4e4f-adf7510a0000 pid=2641 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=d10fcd64-1900-0000-4e4f-adf7510a0000 pid=2641 execve guuid=e69afe64-1900-0000-4e4f-adf7530a0000 pid=2643 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=e69afe64-1900-0000-4e4f-adf7530a0000 pid=2643 execve guuid=756d3b65-1900-0000-4e4f-adf7550a0000 pid=2645 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=756d3b65-1900-0000-4e4f-adf7550a0000 pid=2645 execve guuid=79ec6765-1900-0000-4e4f-adf7560a0000 pid=2646 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=79ec6765-1900-0000-4e4f-adf7560a0000 pid=2646 clone guuid=7b938265-1900-0000-4e4f-adf7580a0000 pid=2648 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=7b938265-1900-0000-4e4f-adf7580a0000 pid=2648 execve guuid=665da765-1900-0000-4e4f-adf7590a0000 pid=2649 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=665da765-1900-0000-4e4f-adf7590a0000 pid=2649 execve guuid=00dfce65-1900-0000-4e4f-adf75a0a0000 pid=2650 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=00dfce65-1900-0000-4e4f-adf75a0a0000 pid=2650 execve guuid=3686f065-1900-0000-4e4f-adf75b0a0000 pid=2651 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=3686f065-1900-0000-4e4f-adf75b0a0000 pid=2651 clone guuid=95d4f865-1900-0000-4e4f-adf75c0a0000 pid=2652 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=95d4f865-1900-0000-4e4f-adf75c0a0000 pid=2652 execve guuid=d27c2466-1900-0000-4e4f-adf75e0a0000 pid=2654 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=d27c2466-1900-0000-4e4f-adf75e0a0000 pid=2654 execve guuid=40156066-1900-0000-4e4f-adf7600a0000 pid=2656 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=40156066-1900-0000-4e4f-adf7600a0000 pid=2656 execve guuid=d5c58f66-1900-0000-4e4f-adf7610a0000 pid=2657 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=d5c58f66-1900-0000-4e4f-adf7610a0000 pid=2657 clone guuid=94b5b466-1900-0000-4e4f-adf7630a0000 pid=2659 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=94b5b466-1900-0000-4e4f-adf7630a0000 pid=2659 execve guuid=569fe066-1900-0000-4e4f-adf7640a0000 pid=2660 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=569fe066-1900-0000-4e4f-adf7640a0000 pid=2660 execve guuid=39e41467-1900-0000-4e4f-adf7660a0000 pid=2662 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=39e41467-1900-0000-4e4f-adf7660a0000 pid=2662 execve guuid=ff984f67-1900-0000-4e4f-adf7680a0000 pid=2664 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=ff984f67-1900-0000-4e4f-adf7680a0000 pid=2664 clone guuid=593c6467-1900-0000-4e4f-adf7690a0000 pid=2665 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=593c6467-1900-0000-4e4f-adf7690a0000 pid=2665 execve guuid=84d39a67-1900-0000-4e4f-adf76b0a0000 pid=2667 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=84d39a67-1900-0000-4e4f-adf76b0a0000 pid=2667 execve guuid=89d4dd67-1900-0000-4e4f-adf76d0a0000 pid=2669 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=89d4dd67-1900-0000-4e4f-adf76d0a0000 pid=2669 execve guuid=a8201868-1900-0000-4e4f-adf76f0a0000 pid=2671 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=a8201868-1900-0000-4e4f-adf76f0a0000 pid=2671 clone guuid=d9722768-1900-0000-4e4f-adf7700a0000 pid=2672 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=d9722768-1900-0000-4e4f-adf7700a0000 pid=2672 execve guuid=b37b5c68-1900-0000-4e4f-adf7720a0000 pid=2674 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=b37b5c68-1900-0000-4e4f-adf7720a0000 pid=2674 execve guuid=86cb9068-1900-0000-4e4f-adf7740a0000 pid=2676 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=86cb9068-1900-0000-4e4f-adf7740a0000 pid=2676 execve guuid=9aa1b068-1900-0000-4e4f-adf7750a0000 pid=2677 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=9aa1b068-1900-0000-4e4f-adf7750a0000 pid=2677 clone guuid=9003d468-1900-0000-4e4f-adf7770a0000 pid=2679 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=9003d468-1900-0000-4e4f-adf7770a0000 pid=2679 execve guuid=2a90f968-1900-0000-4e4f-adf7780a0000 pid=2680 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=2a90f968-1900-0000-4e4f-adf7780a0000 pid=2680 execve guuid=32b61d69-1900-0000-4e4f-adf7790a0000 pid=2681 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=32b61d69-1900-0000-4e4f-adf7790a0000 pid=2681 execve guuid=f6263f69-1900-0000-4e4f-adf77b0a0000 pid=2683 /usr/bin/dash guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=f6263f69-1900-0000-4e4f-adf77b0a0000 pid=2683 clone guuid=a3474c69-1900-0000-4e4f-adf77c0a0000 pid=2684 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=a3474c69-1900-0000-4e4f-adf77c0a0000 pid=2684 execve guuid=bd427369-1900-0000-4e4f-adf77d0a0000 pid=2685 /usr/bin/busybox guuid=f954db61-1900-0000-4e4f-adf7330a0000 pid=2611->guuid=bd427369-1900-0000-4e4f-adf77d0a0000 pid=2685 execve
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-10 13:55:41 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 11c6c1093456e9eb949778d8fa9987cc7ffbd678fa2d30268f6e6b2ac2a320fb

(this sample)

  
Delivery method
Distributed via web download

Comments