MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1edfaca721f86dcc5bd3c43f46b25cb8722c5e76e8775fe8da868ca8017c5d96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1edfaca721f86dcc5bd3c43f46b25cb8722c5e76e8775fe8da868ca8017c5d96
SHA3-384 hash: 1af2484f6572e18b79b8683d82448939e450a4f249c33ece94a664fab4923b6acfaa15694286013a18ba463058de15eb
SHA1 hash: 60730d2d7a75e67e795e34dafda7c24399e87e2e
MD5 hash: c12b822ca17394c3431a1296d6045997
humanhash: potato-india-hot-solar
File name:wget.sh
Download: download sample
File size:243 bytes
First seen:2026-05-29 13:56:36 UTC
Last seen:2026-05-30 08:26:26 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:oe1+TAcP5606BAkSWC70XQCP/v094ajV0UGBHBxLv:oewTjP5Pp9F70ACP/vAej1v
TLSH T143D097DC08206C17813ACA03F18B42D2AB5621C322B0D334706E63327E6F0E0BDC6F00
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://85.204.125.76/solo_bot_n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Adware
File Type:
unix shell
First seen:
2026-05-29T11:24:00Z UTC
Last seen:
2026-05-29T12:26:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2f8a84e2-1600-0000-4541-bc96840e0000 pid=3716 /usr/bin/sudo guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728 /tmp/sample.bin guuid=2f8a84e2-1600-0000-4541-bc96840e0000 pid=3716->guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728 execve guuid=255bfde5-1600-0000-4541-bc96920e0000 pid=3730 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=255bfde5-1600-0000-4541-bc96920e0000 pid=3730 execve guuid=d14a58ff-1600-0000-4541-bc96e70e0000 pid=3815 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=d14a58ff-1600-0000-4541-bc96e70e0000 pid=3815 execve guuid=361db3ff-1600-0000-4541-bc96e80e0000 pid=3816 /usr/bin/bash guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=361db3ff-1600-0000-4541-bc96e80e0000 pid=3816 clone guuid=9863c9ff-1600-0000-4541-bc96ea0e0000 pid=3818 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=9863c9ff-1600-0000-4541-bc96ea0e0000 pid=3818 execve guuid=40629d17-1700-0000-4541-bc962e0f0000 pid=3886 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=40629d17-1700-0000-4541-bc962e0f0000 pid=3886 execve guuid=22760018-1700-0000-4541-bc96310f0000 pid=3889 /usr/bin/bash guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=22760018-1700-0000-4541-bc96310f0000 pid=3889 clone guuid=f7d31718-1700-0000-4541-bc96330f0000 pid=3891 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=f7d31718-1700-0000-4541-bc96330f0000 pid=3891 execve guuid=b5669e33-1700-0000-4541-bc96850f0000 pid=3973 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=b5669e33-1700-0000-4541-bc96850f0000 pid=3973 execve guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975 /tmp/bot_x64 guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975 execve guuid=a99ee433-1700-0000-4541-bc96880f0000 pid=3976 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=a99ee433-1700-0000-4541-bc96880f0000 pid=3976 execve guuid=4497475a-1700-0000-4541-bc962b100000 pid=4139 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=4497475a-1700-0000-4541-bc962b100000 pid=4139 execve guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143 /tmp/bot_i586 guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143 execve guuid=750a8b5a-1700-0000-4541-bc9630100000 pid=4144 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=750a8b5a-1700-0000-4541-bc9630100000 pid=4144 execve guuid=22b4b96f-1700-0000-4541-bc96a5100000 pid=4261 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=22b4b96f-1700-0000-4541-bc96a5100000 pid=4261 execve guuid=0b1afb6f-1700-0000-4541-bc96a6100000 pid=4262 /usr/bin/bash guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=0b1afb6f-1700-0000-4541-bc96a6100000 pid=4262 clone guuid=02290470-1700-0000-4541-bc96a7100000 pid=4263 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=02290470-1700-0000-4541-bc96a7100000 pid=4263 execve guuid=1f16ce84-1700-0000-4541-bc960b110000 pid=4363 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=1f16ce84-1700-0000-4541-bc960b110000 pid=4363 execve guuid=667c1e85-1700-0000-4541-bc960d110000 pid=4365 /usr/bin/bash guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=667c1e85-1700-0000-4541-bc960d110000 pid=4365 clone guuid=c7242685-1700-0000-4541-bc960e110000 pid=4366 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=c7242685-1700-0000-4541-bc960e110000 pid=4366 execve guuid=ad19249e-1700-0000-4541-bc9663110000 pid=4451 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=ad19249e-1700-0000-4541-bc9663110000 pid=4451 execve guuid=4081a99e-1700-0000-4541-bc9667110000 pid=4455 /usr/bin/bash guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=4081a99e-1700-0000-4541-bc9667110000 pid=4455 clone guuid=d6c2b39e-1700-0000-4541-bc9668110000 pid=4456 /usr/bin/wget net send-data write-file guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=d6c2b39e-1700-0000-4541-bc9668110000 pid=4456 execve guuid=5aaea8b4-1700-0000-4541-bc96a1110000 pid=4513 /usr/bin/chmod guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=5aaea8b4-1700-0000-4541-bc96a1110000 pid=4513 execve guuid=394424b5-1700-0000-4541-bc96a3110000 pid=4515 /usr/bin/bash zombie guuid=b67c02e5-1600-0000-4541-bc96900e0000 pid=3728->guuid=394424b5-1700-0000-4541-bc96a3110000 pid=4515 clone f02c14ef-f735-5e79-81f5-063b232980ef 85.204.125.76:80 guuid=255bfde5-1600-0000-4541-bc96920e0000 pid=3730->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=9863c9ff-1600-0000-4541-bc96ea0e0000 pid=3818->f02c14ef-f735-5e79-81f5-063b232980ef send: 142B guuid=f7d31718-1700-0000-4541-bc96330f0000 pid=3891->f02c14ef-f735-5e79-81f5-063b232980ef send: 140B guuid=884d0334-1700-0000-4541-bc96890f0000 pid=3977 /usr/bin/dash guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=884d0334-1700-0000-4541-bc96890f0000 pid=3977 execve guuid=1bd6f136-1700-0000-4541-bc96980f0000 pid=3992 /usr/bin/dash guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=1bd6f136-1700-0000-4541-bc96980f0000 pid=3992 execve guuid=62a39739-1700-0000-4541-bc96a60f0000 pid=4006 /usr/bin/dash guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=62a39739-1700-0000-4541-bc96a60f0000 pid=4006 execve guuid=3709093c-1700-0000-4541-bc96b20f0000 pid=4018 /usr/bin/dash guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=3709093c-1700-0000-4541-bc96b20f0000 pid=4018 execve guuid=0ee18c3e-1700-0000-4541-bc96c00f0000 pid=4032 /usr/bin/dash guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=0ee18c3e-1700-0000-4541-bc96c00f0000 pid=4032 execve guuid=55e61641-1700-0000-4541-bc96d00f0000 pid=4048 /usr/bin/dash guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=55e61641-1700-0000-4541-bc96d00f0000 pid=4048 execve guuid=8c07a541-1700-0000-4541-bc96d80f0000 pid=4056 /tmp/bot_x64 net zombie guuid=053bde33-1700-0000-4541-bc96870f0000 pid=3975->guuid=8c07a541-1700-0000-4541-bc96d80f0000 pid=4056 clone guuid=a99ee433-1700-0000-4541-bc96880f0000 pid=3976->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=43302f34-1700-0000-4541-bc968a0f0000 pid=3978 /usr/bin/pgrep zombie guuid=884d0334-1700-0000-4541-bc96890f0000 pid=3977->guuid=43302f34-1700-0000-4541-bc968a0f0000 pid=3978 execve guuid=79bd1c37-1700-0000-4541-bc96990f0000 pid=3993 /usr/bin/pgrep guuid=1bd6f136-1700-0000-4541-bc96980f0000 pid=3992->guuid=79bd1c37-1700-0000-4541-bc96990f0000 pid=3993 execve guuid=e025bf39-1700-0000-4541-bc96aa0f0000 pid=4010 /usr/bin/pgrep guuid=62a39739-1700-0000-4541-bc96a60f0000 pid=4006->guuid=e025bf39-1700-0000-4541-bc96aa0f0000 pid=4010 execve guuid=dfc22f3c-1700-0000-4541-bc96b30f0000 pid=4019 /usr/bin/pgrep guuid=3709093c-1700-0000-4541-bc96b20f0000 pid=4018->guuid=dfc22f3c-1700-0000-4541-bc96b30f0000 pid=4019 execve guuid=977cb53e-1700-0000-4541-bc96c20f0000 pid=4034 /usr/bin/pgrep guuid=0ee18c3e-1700-0000-4541-bc96c00f0000 pid=4032->guuid=977cb53e-1700-0000-4541-bc96c20f0000 pid=4034 execve guuid=51c33d41-1700-0000-4541-bc96d10f0000 pid=4049 /usr/bin/dash guuid=55e61641-1700-0000-4541-bc96d00f0000 pid=4048->guuid=51c33d41-1700-0000-4541-bc96d10f0000 pid=4049 clone guuid=186b4341-1700-0000-4541-bc96d20f0000 pid=4050 /usr/bin/dash guuid=55e61641-1700-0000-4541-bc96d00f0000 pid=4048->guuid=186b4341-1700-0000-4541-bc96d20f0000 pid=4050 clone guuid=06674741-1700-0000-4541-bc96d30f0000 pid=4051 /usr/bin/dash guuid=51c33d41-1700-0000-4541-bc96d10f0000 pid=4049->guuid=06674741-1700-0000-4541-bc96d30f0000 pid=4051 clone guuid=0f314b41-1700-0000-4541-bc96d40f0000 pid=4052 /usr/bin/grep guuid=51c33d41-1700-0000-4541-bc96d10f0000 pid=4049->guuid=0f314b41-1700-0000-4541-bc96d40f0000 pid=4052 execve 53c94186-be21-557b-8480-07ed948c978d 85.204.125.76:12345 guuid=8c07a541-1700-0000-4541-bc96d80f0000 pid=4056->53c94186-be21-557b-8480-07ed948c978d con guuid=0369b15a-1700-0000-4541-bc9631100000 pid=4145 /usr/bin/dash guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=0369b15a-1700-0000-4541-bc9631100000 pid=4145 execve guuid=470b125d-1700-0000-4541-bc9643100000 pid=4163 /usr/bin/dash guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=470b125d-1700-0000-4541-bc9643100000 pid=4163 execve guuid=d09e955f-1700-0000-4541-bc9652100000 pid=4178 /usr/bin/dash guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=d09e955f-1700-0000-4541-bc9652100000 pid=4178 execve guuid=5aef4062-1700-0000-4541-bc965d100000 pid=4189 /usr/bin/dash guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=5aef4062-1700-0000-4541-bc965d100000 pid=4189 execve guuid=87e9c264-1700-0000-4541-bc966c100000 pid=4204 /usr/bin/dash guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=87e9c264-1700-0000-4541-bc966c100000 pid=4204 execve guuid=cc3c2b67-1700-0000-4541-bc9678100000 pid=4216 /usr/bin/dash guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=cc3c2b67-1700-0000-4541-bc9678100000 pid=4216 execve guuid=32aec267-1700-0000-4541-bc9680100000 pid=4224 /tmp/bot_i586 net zombie guuid=9906845a-1700-0000-4541-bc962f100000 pid=4143->guuid=32aec267-1700-0000-4541-bc9680100000 pid=4224 clone guuid=750a8b5a-1700-0000-4541-bc9630100000 pid=4144->f02c14ef-f735-5e79-81f5-063b232980ef send: 141B guuid=8c25d55a-1700-0000-4541-bc9635100000 pid=4149 /usr/bin/pgrep zombie guuid=0369b15a-1700-0000-4541-bc9631100000 pid=4145->guuid=8c25d55a-1700-0000-4541-bc9635100000 pid=4149 execve guuid=6072425d-1700-0000-4541-bc9644100000 pid=4164 /usr/bin/pgrep guuid=470b125d-1700-0000-4541-bc9643100000 pid=4163->guuid=6072425d-1700-0000-4541-bc9644100000 pid=4164 execve guuid=6d65d05f-1700-0000-4541-bc9653100000 pid=4179 /usr/bin/pgrep guuid=d09e955f-1700-0000-4541-bc9652100000 pid=4178->guuid=6d65d05f-1700-0000-4541-bc9653100000 pid=4179 execve guuid=1b7c6762-1700-0000-4541-bc965e100000 pid=4190 /usr/bin/pgrep guuid=5aef4062-1700-0000-4541-bc965d100000 pid=4189->guuid=1b7c6762-1700-0000-4541-bc965e100000 pid=4190 execve guuid=6125e964-1700-0000-4541-bc966f100000 pid=4207 /usr/bin/pgrep guuid=87e9c264-1700-0000-4541-bc966c100000 pid=4204->guuid=6125e964-1700-0000-4541-bc966f100000 pid=4207 execve guuid=475e5467-1700-0000-4541-bc967a100000 pid=4218 /usr/bin/dash guuid=cc3c2b67-1700-0000-4541-bc9678100000 pid=4216->guuid=475e5467-1700-0000-4541-bc967a100000 pid=4218 clone guuid=cf0e5867-1700-0000-4541-bc967b100000 pid=4219 /usr/bin/dash guuid=cc3c2b67-1700-0000-4541-bc9678100000 pid=4216->guuid=cf0e5867-1700-0000-4541-bc967b100000 pid=4219 clone guuid=81006167-1700-0000-4541-bc967e100000 pid=4222 /usr/bin/dash guuid=475e5467-1700-0000-4541-bc967a100000 pid=4218->guuid=81006167-1700-0000-4541-bc967e100000 pid=4222 clone guuid=5eae6467-1700-0000-4541-bc967f100000 pid=4223 /usr/bin/grep guuid=475e5467-1700-0000-4541-bc967a100000 pid=4218->guuid=5eae6467-1700-0000-4541-bc967f100000 pid=4223 execve guuid=32aec267-1700-0000-4541-bc9680100000 pid=4224->53c94186-be21-557b-8480-07ed948c978d con guuid=02290470-1700-0000-4541-bc96a7100000 pid=4263->f02c14ef-f735-5e79-81f5-063b232980ef send: 143B guuid=c7242685-1700-0000-4541-bc960e110000 pid=4366->f02c14ef-f735-5e79-81f5-063b232980ef send: 140B guuid=d6c2b39e-1700-0000-4541-bc9668110000 pid=4456->f02c14ef-f735-5e79-81f5-063b232980ef send: 140B
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1edfaca721f86dcc5bd3c43f46b25cb8722c5e76e8775fe8da868ca8017c5d96

(this sample)

  
Delivery method
Distributed via web download

Comments