MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 152a8f82993e07eac6b11e35d5534cb38308e03b400afee1fffa8f213d7432af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 152a8f82993e07eac6b11e35d5534cb38308e03b400afee1fffa8f213d7432af
SHA3-384 hash: cc629ffa3103f07c7bee69d2b16a0b5aab5a66d00a80197c28bf5427af7206d1df48e7d252365fba5b58b7c58323e063
SHA1 hash: 8026fdc61880e9e7059cf9b6aecfd6d32fa393f3
MD5 hash: 5b88bcc90865bf611710a87196263ef1
humanhash: leopard-charlie-angel-magazine
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-10 20:15:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkaVIWtAZIgib3Ivc8IOxqxjbI1YauD:kXCKysE2hi0ziQvZohaVGlibn8/EXgY7
TLSH T15B0155DA8009D7A081DAE89E729751907411C3CBA5454FF87EEC403D9BB9A68B01AFA9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/h1FOn/an/aelf ua-wget
http://188.132.232.81/TVhn/an/aelf ua-wget
http://188.132.232.81/QaXxn/an/aelf ua-wget
http://188.132.232.81/pHfn/an/aelf ua-wget
http://188.132.232.81/q2mtn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-10T17:21:00Z UTC
Last seen:
2026-06-10T18:15:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=832cf002-1900-0000-0581-cf7ea8090000 pid=2472 /usr/bin/sudo guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478 /tmp/sample.bin write-file guuid=832cf002-1900-0000-0581-cf7ea8090000 pid=2472->guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478 execve guuid=ea63ea04-1900-0000-0581-cf7eaf090000 pid=2479 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=ea63ea04-1900-0000-0581-cf7eaf090000 pid=2479 execve guuid=24b27a05-1900-0000-0581-cf7eb1090000 pid=2481 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=24b27a05-1900-0000-0581-cf7eb1090000 pid=2481 execve guuid=653d9d06-1900-0000-0581-cf7eb4090000 pid=2484 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=653d9d06-1900-0000-0581-cf7eb4090000 pid=2484 execve guuid=a7367e07-1900-0000-0581-cf7eb7090000 pid=2487 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=a7367e07-1900-0000-0581-cf7eb7090000 pid=2487 execve guuid=245a4308-1900-0000-0581-cf7eba090000 pid=2490 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=245a4308-1900-0000-0581-cf7eba090000 pid=2490 execve guuid=f1f6a008-1900-0000-0581-cf7ebb090000 pid=2491 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=f1f6a008-1900-0000-0581-cf7ebb090000 pid=2491 execve guuid=aeae4509-1900-0000-0581-cf7ebf090000 pid=2495 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=aeae4509-1900-0000-0581-cf7ebf090000 pid=2495 execve guuid=d98ddf09-1900-0000-0581-cf7ec2090000 pid=2498 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d98ddf09-1900-0000-0581-cf7ec2090000 pid=2498 execve guuid=bcd1490a-1900-0000-0581-cf7ec4090000 pid=2500 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=bcd1490a-1900-0000-0581-cf7ec4090000 pid=2500 execve guuid=1526bd0a-1900-0000-0581-cf7ec5090000 pid=2501 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=1526bd0a-1900-0000-0581-cf7ec5090000 pid=2501 execve guuid=9ab7380b-1900-0000-0581-cf7ec6090000 pid=2502 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=9ab7380b-1900-0000-0581-cf7ec6090000 pid=2502 execve guuid=4036b90b-1900-0000-0581-cf7ec7090000 pid=2503 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=4036b90b-1900-0000-0581-cf7ec7090000 pid=2503 execve guuid=c8d0470c-1900-0000-0581-cf7ec8090000 pid=2504 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c8d0470c-1900-0000-0581-cf7ec8090000 pid=2504 execve guuid=0e9bc50c-1900-0000-0581-cf7ec9090000 pid=2505 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=0e9bc50c-1900-0000-0581-cf7ec9090000 pid=2505 execve guuid=7a7aa90d-1900-0000-0581-cf7ecb090000 pid=2507 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=7a7aa90d-1900-0000-0581-cf7ecb090000 pid=2507 execve guuid=613f230e-1900-0000-0581-cf7ece090000 pid=2510 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=613f230e-1900-0000-0581-cf7ece090000 pid=2510 execve guuid=b0bfa00e-1900-0000-0581-cf7ed0090000 pid=2512 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b0bfa00e-1900-0000-0581-cf7ed0090000 pid=2512 execve guuid=376a040f-1900-0000-0581-cf7ed3090000 pid=2515 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=376a040f-1900-0000-0581-cf7ed3090000 pid=2515 execve guuid=7154f20f-1900-0000-0581-cf7ed7090000 pid=2519 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=7154f20f-1900-0000-0581-cf7ed7090000 pid=2519 execve guuid=fe9f9410-1900-0000-0581-cf7eda090000 pid=2522 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=fe9f9410-1900-0000-0581-cf7eda090000 pid=2522 execve guuid=a6962d11-1900-0000-0581-cf7edc090000 pid=2524 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=a6962d11-1900-0000-0581-cf7edc090000 pid=2524 execve guuid=b12ed211-1900-0000-0581-cf7edd090000 pid=2525 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b12ed211-1900-0000-0581-cf7edd090000 pid=2525 execve guuid=cc6c6012-1900-0000-0581-cf7ede090000 pid=2526 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=cc6c6012-1900-0000-0581-cf7ede090000 pid=2526 execve guuid=1763de12-1900-0000-0581-cf7ee1090000 pid=2529 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=1763de12-1900-0000-0581-cf7ee1090000 pid=2529 execve guuid=f7fb6413-1900-0000-0581-cf7ee4090000 pid=2532 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=f7fb6413-1900-0000-0581-cf7ee4090000 pid=2532 execve guuid=0698ed13-1900-0000-0581-cf7ee7090000 pid=2535 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=0698ed13-1900-0000-0581-cf7ee7090000 pid=2535 execve guuid=ef126814-1900-0000-0581-cf7ee9090000 pid=2537 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=ef126814-1900-0000-0581-cf7ee9090000 pid=2537 execve guuid=df91c514-1900-0000-0581-cf7eeb090000 pid=2539 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=df91c514-1900-0000-0581-cf7eeb090000 pid=2539 execve guuid=cf062615-1900-0000-0581-cf7eed090000 pid=2541 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=cf062615-1900-0000-0581-cf7eed090000 pid=2541 execve guuid=e23b8915-1900-0000-0581-cf7eef090000 pid=2543 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=e23b8915-1900-0000-0581-cf7eef090000 pid=2543 execve guuid=f437e515-1900-0000-0581-cf7ef1090000 pid=2545 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=f437e515-1900-0000-0581-cf7ef1090000 pid=2545 execve guuid=59bc4616-1900-0000-0581-cf7ef2090000 pid=2546 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=59bc4616-1900-0000-0581-cf7ef2090000 pid=2546 execve guuid=dfaae216-1900-0000-0581-cf7ef4090000 pid=2548 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=dfaae216-1900-0000-0581-cf7ef4090000 pid=2548 execve guuid=d8637117-1900-0000-0581-cf7ef7090000 pid=2551 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d8637117-1900-0000-0581-cf7ef7090000 pid=2551 execve guuid=91b2cb17-1900-0000-0581-cf7ef9090000 pid=2553 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=91b2cb17-1900-0000-0581-cf7ef9090000 pid=2553 execve guuid=81292c18-1900-0000-0581-cf7efb090000 pid=2555 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=81292c18-1900-0000-0581-cf7efb090000 pid=2555 execve guuid=1aad8a18-1900-0000-0581-cf7efd090000 pid=2557 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=1aad8a18-1900-0000-0581-cf7efd090000 pid=2557 execve guuid=a458ee18-1900-0000-0581-cf7eff090000 pid=2559 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=a458ee18-1900-0000-0581-cf7eff090000 pid=2559 execve guuid=16954819-1900-0000-0581-cf7e010a0000 pid=2561 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=16954819-1900-0000-0581-cf7e010a0000 pid=2561 execve guuid=231ba919-1900-0000-0581-cf7e040a0000 pid=2564 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=231ba919-1900-0000-0581-cf7e040a0000 pid=2564 execve guuid=b684041a-1900-0000-0581-cf7e050a0000 pid=2565 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b684041a-1900-0000-0581-cf7e050a0000 pid=2565 execve guuid=76eb681a-1900-0000-0581-cf7e070a0000 pid=2567 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=76eb681a-1900-0000-0581-cf7e070a0000 pid=2567 execve guuid=30b4c61a-1900-0000-0581-cf7e090a0000 pid=2569 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=30b4c61a-1900-0000-0581-cf7e090a0000 pid=2569 execve guuid=c9382d1b-1900-0000-0581-cf7e0b0a0000 pid=2571 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c9382d1b-1900-0000-0581-cf7e0b0a0000 pid=2571 execve guuid=7076861b-1900-0000-0581-cf7e0d0a0000 pid=2573 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=7076861b-1900-0000-0581-cf7e0d0a0000 pid=2573 execve guuid=23c0e01b-1900-0000-0581-cf7e0f0a0000 pid=2575 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=23c0e01b-1900-0000-0581-cf7e0f0a0000 pid=2575 execve guuid=b5303d1c-1900-0000-0581-cf7e120a0000 pid=2578 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b5303d1c-1900-0000-0581-cf7e120a0000 pid=2578 execve guuid=e6d3091d-1900-0000-0581-cf7e160a0000 pid=2582 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=e6d3091d-1900-0000-0581-cf7e160a0000 pid=2582 execve guuid=78f8741d-1900-0000-0581-cf7e180a0000 pid=2584 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=78f8741d-1900-0000-0581-cf7e180a0000 pid=2584 execve guuid=d80a151e-1900-0000-0581-cf7e1a0a0000 pid=2586 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d80a151e-1900-0000-0581-cf7e1a0a0000 pid=2586 execve guuid=05df871e-1900-0000-0581-cf7e1b0a0000 pid=2587 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=05df871e-1900-0000-0581-cf7e1b0a0000 pid=2587 execve guuid=d261061f-1900-0000-0581-cf7e1c0a0000 pid=2588 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d261061f-1900-0000-0581-cf7e1c0a0000 pid=2588 execve guuid=3fde7c1f-1900-0000-0581-cf7e1d0a0000 pid=2589 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=3fde7c1f-1900-0000-0581-cf7e1d0a0000 pid=2589 execve guuid=054f3620-1900-0000-0581-cf7e1f0a0000 pid=2591 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=054f3620-1900-0000-0581-cf7e1f0a0000 pid=2591 execve guuid=0bbcd020-1900-0000-0581-cf7e220a0000 pid=2594 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=0bbcd020-1900-0000-0581-cf7e220a0000 pid=2594 execve guuid=251d6521-1900-0000-0581-cf7e250a0000 pid=2597 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=251d6521-1900-0000-0581-cf7e250a0000 pid=2597 execve guuid=7e090622-1900-0000-0581-cf7e270a0000 pid=2599 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=7e090622-1900-0000-0581-cf7e270a0000 pid=2599 execve guuid=c8f57722-1900-0000-0581-cf7e2a0a0000 pid=2602 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c8f57722-1900-0000-0581-cf7e2a0a0000 pid=2602 execve guuid=6387e422-1900-0000-0581-cf7e2c0a0000 pid=2604 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=6387e422-1900-0000-0581-cf7e2c0a0000 pid=2604 execve guuid=3ba74623-1900-0000-0581-cf7e2e0a0000 pid=2606 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=3ba74623-1900-0000-0581-cf7e2e0a0000 pid=2606 execve guuid=bd7ca823-1900-0000-0581-cf7e300a0000 pid=2608 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=bd7ca823-1900-0000-0581-cf7e300a0000 pid=2608 execve guuid=314f0724-1900-0000-0581-cf7e330a0000 pid=2611 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=314f0724-1900-0000-0581-cf7e330a0000 pid=2611 execve guuid=cc899c24-1900-0000-0581-cf7e350a0000 pid=2613 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=cc899c24-1900-0000-0581-cf7e350a0000 pid=2613 execve guuid=5cf92025-1900-0000-0581-cf7e370a0000 pid=2615 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=5cf92025-1900-0000-0581-cf7e370a0000 pid=2615 execve guuid=22d1a825-1900-0000-0581-cf7e380a0000 pid=2616 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=22d1a825-1900-0000-0581-cf7e380a0000 pid=2616 execve guuid=c4e12f26-1900-0000-0581-cf7e390a0000 pid=2617 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c4e12f26-1900-0000-0581-cf7e390a0000 pid=2617 execve guuid=48499826-1900-0000-0581-cf7e3c0a0000 pid=2620 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=48499826-1900-0000-0581-cf7e3c0a0000 pid=2620 execve guuid=03850b27-1900-0000-0581-cf7e3e0a0000 pid=2622 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=03850b27-1900-0000-0581-cf7e3e0a0000 pid=2622 execve guuid=eb646b27-1900-0000-0581-cf7e410a0000 pid=2625 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=eb646b27-1900-0000-0581-cf7e410a0000 pid=2625 execve guuid=23ffd627-1900-0000-0581-cf7e430a0000 pid=2627 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=23ffd627-1900-0000-0581-cf7e430a0000 pid=2627 execve guuid=bbeb3f28-1900-0000-0581-cf7e450a0000 pid=2629 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=bbeb3f28-1900-0000-0581-cf7e450a0000 pid=2629 execve guuid=b2269f28-1900-0000-0581-cf7e470a0000 pid=2631 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b2269f28-1900-0000-0581-cf7e470a0000 pid=2631 execve guuid=b9e5fc28-1900-0000-0581-cf7e490a0000 pid=2633 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b9e5fc28-1900-0000-0581-cf7e490a0000 pid=2633 execve guuid=d0a25829-1900-0000-0581-cf7e4b0a0000 pid=2635 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d0a25829-1900-0000-0581-cf7e4b0a0000 pid=2635 execve guuid=36b4ba29-1900-0000-0581-cf7e4d0a0000 pid=2637 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=36b4ba29-1900-0000-0581-cf7e4d0a0000 pid=2637 execve guuid=dd141c2a-1900-0000-0581-cf7e4f0a0000 pid=2639 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=dd141c2a-1900-0000-0581-cf7e4f0a0000 pid=2639 execve guuid=30977b2a-1900-0000-0581-cf7e520a0000 pid=2642 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=30977b2a-1900-0000-0581-cf7e520a0000 pid=2642 execve guuid=3296f62a-1900-0000-0581-cf7e540a0000 pid=2644 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=3296f62a-1900-0000-0581-cf7e540a0000 pid=2644 execve guuid=509c6b2b-1900-0000-0581-cf7e560a0000 pid=2646 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=509c6b2b-1900-0000-0581-cf7e560a0000 pid=2646 execve guuid=1ecef32b-1900-0000-0581-cf7e580a0000 pid=2648 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=1ecef32b-1900-0000-0581-cf7e580a0000 pid=2648 execve guuid=eda68e2c-1900-0000-0581-cf7e5b0a0000 pid=2651 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=eda68e2c-1900-0000-0581-cf7e5b0a0000 pid=2651 execve guuid=662c0b2d-1900-0000-0581-cf7e5e0a0000 pid=2654 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=662c0b2d-1900-0000-0581-cf7e5e0a0000 pid=2654 execve guuid=452f7d2d-1900-0000-0581-cf7e600a0000 pid=2656 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=452f7d2d-1900-0000-0581-cf7e600a0000 pid=2656 execve guuid=c743e62d-1900-0000-0581-cf7e620a0000 pid=2658 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c743e62d-1900-0000-0581-cf7e620a0000 pid=2658 execve guuid=83284c2e-1900-0000-0581-cf7e650a0000 pid=2661 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=83284c2e-1900-0000-0581-cf7e650a0000 pid=2661 execve guuid=7913ad2e-1900-0000-0581-cf7e670a0000 pid=2663 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=7913ad2e-1900-0000-0581-cf7e670a0000 pid=2663 execve guuid=f8cc3c2f-1900-0000-0581-cf7e6a0a0000 pid=2666 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=f8cc3c2f-1900-0000-0581-cf7e6a0a0000 pid=2666 execve guuid=a02be42f-1900-0000-0581-cf7e6d0a0000 pid=2669 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=a02be42f-1900-0000-0581-cf7e6d0a0000 pid=2669 execve guuid=3ccefa30-1900-0000-0581-cf7e700a0000 pid=2672 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=3ccefa30-1900-0000-0581-cf7e700a0000 pid=2672 execve guuid=9de89231-1900-0000-0581-cf7e730a0000 pid=2675 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=9de89231-1900-0000-0581-cf7e730a0000 pid=2675 execve guuid=3fb22232-1900-0000-0581-cf7e760a0000 pid=2678 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=3fb22232-1900-0000-0581-cf7e760a0000 pid=2678 execve guuid=c11c9632-1900-0000-0581-cf7e770a0000 pid=2679 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c11c9632-1900-0000-0581-cf7e770a0000 pid=2679 execve guuid=8f680a33-1900-0000-0581-cf7e7a0a0000 pid=2682 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=8f680a33-1900-0000-0581-cf7e7a0a0000 pid=2682 execve guuid=157a8033-1900-0000-0581-cf7e7c0a0000 pid=2684 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=157a8033-1900-0000-0581-cf7e7c0a0000 pid=2684 execve guuid=b770f633-1900-0000-0581-cf7e7f0a0000 pid=2687 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b770f633-1900-0000-0581-cf7e7f0a0000 pid=2687 execve guuid=568a7334-1900-0000-0581-cf7e810a0000 pid=2689 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=568a7334-1900-0000-0581-cf7e810a0000 pid=2689 execve guuid=6325fc34-1900-0000-0581-cf7e830a0000 pid=2691 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=6325fc34-1900-0000-0581-cf7e830a0000 pid=2691 execve guuid=106e9d35-1900-0000-0581-cf7e860a0000 pid=2694 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=106e9d35-1900-0000-0581-cf7e860a0000 pid=2694 execve guuid=bbe92936-1900-0000-0581-cf7e880a0000 pid=2696 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=bbe92936-1900-0000-0581-cf7e880a0000 pid=2696 execve guuid=e540ca36-1900-0000-0581-cf7e8b0a0000 pid=2699 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=e540ca36-1900-0000-0581-cf7e8b0a0000 pid=2699 execve guuid=ba914a37-1900-0000-0581-cf7e8d0a0000 pid=2701 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=ba914a37-1900-0000-0581-cf7e8d0a0000 pid=2701 execve guuid=d945b137-1900-0000-0581-cf7e8f0a0000 pid=2703 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d945b137-1900-0000-0581-cf7e8f0a0000 pid=2703 execve guuid=b63a3f38-1900-0000-0581-cf7e920a0000 pid=2706 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b63a3f38-1900-0000-0581-cf7e920a0000 pid=2706 execve guuid=9c0cd638-1900-0000-0581-cf7e940a0000 pid=2708 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=9c0cd638-1900-0000-0581-cf7e940a0000 pid=2708 execve guuid=02af8e39-1900-0000-0581-cf7e970a0000 pid=2711 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=02af8e39-1900-0000-0581-cf7e970a0000 pid=2711 execve guuid=b952303a-1900-0000-0581-cf7e990a0000 pid=2713 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=b952303a-1900-0000-0581-cf7e990a0000 pid=2713 execve guuid=c7abca3a-1900-0000-0581-cf7e9c0a0000 pid=2716 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c7abca3a-1900-0000-0581-cf7e9c0a0000 pid=2716 execve guuid=18825d3b-1900-0000-0581-cf7e9e0a0000 pid=2718 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=18825d3b-1900-0000-0581-cf7e9e0a0000 pid=2718 execve guuid=7b3a023c-1900-0000-0581-cf7ea10a0000 pid=2721 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=7b3a023c-1900-0000-0581-cf7ea10a0000 pid=2721 execve guuid=ef6fa03c-1900-0000-0581-cf7ea40a0000 pid=2724 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=ef6fa03c-1900-0000-0581-cf7ea40a0000 pid=2724 execve guuid=85cf2e3d-1900-0000-0581-cf7ea70a0000 pid=2727 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=85cf2e3d-1900-0000-0581-cf7ea70a0000 pid=2727 execve guuid=df2a133e-1900-0000-0581-cf7eab0a0000 pid=2731 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=df2a133e-1900-0000-0581-cf7eab0a0000 pid=2731 execve guuid=1b53903e-1900-0000-0581-cf7eae0a0000 pid=2734 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=1b53903e-1900-0000-0581-cf7eae0a0000 pid=2734 execve guuid=07c3003f-1900-0000-0581-cf7eb00a0000 pid=2736 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=07c3003f-1900-0000-0581-cf7eb00a0000 pid=2736 execve guuid=8f60953f-1900-0000-0581-cf7eb40a0000 pid=2740 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=8f60953f-1900-0000-0581-cf7eb40a0000 pid=2740 execve guuid=80832840-1900-0000-0581-cf7eb70a0000 pid=2743 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=80832840-1900-0000-0581-cf7eb70a0000 pid=2743 execve guuid=4d349e40-1900-0000-0581-cf7eb90a0000 pid=2745 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=4d349e40-1900-0000-0581-cf7eb90a0000 pid=2745 execve guuid=45191f41-1900-0000-0581-cf7ebb0a0000 pid=2747 /usr/bin/ls guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=45191f41-1900-0000-0581-cf7ebb0a0000 pid=2747 execve guuid=1256a541-1900-0000-0581-cf7ebe0a0000 pid=2750 /usr/bin/rm guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=1256a541-1900-0000-0581-cf7ebe0a0000 pid=2750 execve guuid=d508f241-1900-0000-0581-cf7ec00a0000 pid=2752 /usr/bin/wget net send-data write-file guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d508f241-1900-0000-0581-cf7ec00a0000 pid=2752 execve guuid=91baa985-1900-0000-0581-cf7e4b0b0000 pid=2891 /usr/bin/chmod guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=91baa985-1900-0000-0581-cf7e4b0b0000 pid=2891 execve guuid=d41c1586-1900-0000-0581-cf7e4c0b0000 pid=2892 /usr/bin/dash guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=d41c1586-1900-0000-0581-cf7e4c0b0000 pid=2892 clone guuid=e9352287-1900-0000-0581-cf7e4f0b0000 pid=2895 /usr/bin/rm guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=e9352287-1900-0000-0581-cf7e4f0b0000 pid=2895 execve guuid=e8739487-1900-0000-0581-cf7e500b0000 pid=2896 /usr/bin/wget net send-data write-file guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=e8739487-1900-0000-0581-cf7e500b0000 pid=2896 execve guuid=867cebc4-1900-0000-0581-cf7ebc0b0000 pid=3004 /usr/bin/chmod guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=867cebc4-1900-0000-0581-cf7ebc0b0000 pid=3004 execve guuid=ed6048c5-1900-0000-0581-cf7ebd0b0000 pid=3005 /usr/bin/dash guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=ed6048c5-1900-0000-0581-cf7ebd0b0000 pid=3005 clone guuid=69e833c6-1900-0000-0581-cf7ec10b0000 pid=3009 /usr/bin/rm guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=69e833c6-1900-0000-0581-cf7ec10b0000 pid=3009 execve guuid=fa208ec6-1900-0000-0581-cf7ec30b0000 pid=3011 /usr/bin/wget net send-data write-file guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=fa208ec6-1900-0000-0581-cf7ec30b0000 pid=3011 execve guuid=4b8eaaea-1900-0000-0581-cf7efc0b0000 pid=3068 /usr/bin/chmod guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=4b8eaaea-1900-0000-0581-cf7efc0b0000 pid=3068 execve guuid=91e310eb-1900-0000-0581-cf7efe0b0000 pid=3070 /usr/bin/dash guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=91e310eb-1900-0000-0581-cf7efe0b0000 pid=3070 clone guuid=c43de3ec-1900-0000-0581-cf7e010c0000 pid=3073 /usr/bin/rm guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=c43de3ec-1900-0000-0581-cf7e010c0000 pid=3073 execve guuid=0f9979ed-1900-0000-0581-cf7e020c0000 pid=3074 /usr/bin/wget net send-data write-file guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=0f9979ed-1900-0000-0581-cf7e020c0000 pid=3074 execve guuid=547fac72-1a00-0000-0581-cf7eee0c0000 pid=3310 /usr/bin/chmod guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=547fac72-1a00-0000-0581-cf7eee0c0000 pid=3310 execve guuid=ccc02873-1a00-0000-0581-cf7eef0c0000 pid=3311 /usr/bin/dash guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=ccc02873-1a00-0000-0581-cf7eef0c0000 pid=3311 clone guuid=64afe474-1a00-0000-0581-cf7ef10c0000 pid=3313 /usr/bin/rm guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=64afe474-1a00-0000-0581-cf7ef10c0000 pid=3313 execve guuid=8d6f2575-1a00-0000-0581-cf7ef20c0000 pid=3314 /usr/bin/wget net send-data write-file guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=8d6f2575-1a00-0000-0581-cf7ef20c0000 pid=3314 execve guuid=47c5c892-1a00-0000-0581-cf7e0c0d0000 pid=3340 /usr/bin/chmod guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=47c5c892-1a00-0000-0581-cf7e0c0d0000 pid=3340 execve guuid=3dee2893-1a00-0000-0581-cf7e0d0d0000 pid=3341 /usr/bin/dash guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=3dee2893-1a00-0000-0581-cf7e0d0d0000 pid=3341 clone guuid=9495da93-1a00-0000-0581-cf7e100d0000 pid=3344 /usr/bin/rm delete-file guuid=51e39a04-1900-0000-0581-cf7eae090000 pid=2478->guuid=9495da93-1a00-0000-0581-cf7e100d0000 pid=3344 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=d508f241-1900-0000-0581-cf7ec00a0000 pid=2752->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=e8739487-1900-0000-0581-cf7e500b0000 pid=2896->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=fa208ec6-1900-0000-0581-cf7ec30b0000 pid=3011->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=0f9979ed-1900-0000-0581-cf7e020c0000 pid=3074->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=8d6f2575-1a00-0000-0581-cf7ef20c0000 pid=3314->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-06-10 20:16:35 UTC
File Type:
Text (Shell)
AV detection:
7 of 23 (30.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 152a8f82993e07eac6b11e35d5534cb38308e03b400afee1fffa8f213d7432af

(this sample)

  
Delivery method
Distributed via web download

Comments