MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20f5bac38fd073fe3b46916e783f8cfa09556ae0ab9a5968de747df33f7cf077. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 20f5bac38fd073fe3b46916e783f8cfa09556ae0ab9a5968de747df33f7cf077
SHA3-384 hash: 7ded708fbef5d404f83e6825907498ab211448090b93ce7064d31b4403377545c09c1b95ee2adb237eb05b1b8207101e
SHA1 hash: 61e5b590d38067a84a8f7607ff9090104b683006
MD5 hash: 1aae2a62a6833e7f9128a16c7b519d7e
humanhash: low-princess-summer-timing
File name:vac
Download: download sample
File size:295 bytes
First seen:2025-10-19 20:48:29 UTC
Last seen:2025-10-20 20:20:17 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+pUKUF2RVYx8iHYf53IKGu4H3FoF/fkVKhOXqIKXD73IKX+N1IEWYq1IKBKW:ZtJ+jRE8KYJPF0ghsOTh4WYO8W
TLSH T184E0C299F853083278748CB9B7DB6855960B920E6E0A55CE3189520AAAE4A50A050453
Magika shell
Reporter juroots
Tags:sh

Intelligence


File Origin
# of uploads :
3
# of downloads :
36
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-19T18:52:00Z UTC
Last seen:
2025-10-21T18:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b263dbf0-2000-0000-b5f6-beebb60b0000 pid=2998 /usr/bin/sudo guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004 /tmp/sample.bin guuid=b263dbf0-2000-0000-b5f6-beebb60b0000 pid=2998->guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004 execve guuid=5a11eff2-2000-0000-b5f6-beebbe0b0000 pid=3006 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=5a11eff2-2000-0000-b5f6-beebbe0b0000 pid=3006 execve guuid=4b43cd05-2100-0000-b5f6-beebf00b0000 pid=3056 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=4b43cd05-2100-0000-b5f6-beebf00b0000 pid=3056 execve guuid=262e0f06-2100-0000-b5f6-beebf20b0000 pid=3058 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=262e0f06-2100-0000-b5f6-beebf20b0000 pid=3058 clone guuid=cfc47807-2100-0000-b5f6-beebf90b0000 pid=3065 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=cfc47807-2100-0000-b5f6-beebf90b0000 pid=3065 execve guuid=6f05f607-2100-0000-b5f6-beebfd0b0000 pid=3069 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=6f05f607-2100-0000-b5f6-beebfd0b0000 pid=3069 execve guuid=5b849417-2100-0000-b5f6-beeb250c0000 pid=3109 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=5b849417-2100-0000-b5f6-beeb250c0000 pid=3109 execve guuid=f3a8e417-2100-0000-b5f6-beeb260c0000 pid=3110 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=f3a8e417-2100-0000-b5f6-beeb260c0000 pid=3110 clone guuid=38f77718-2100-0000-b5f6-beeb280c0000 pid=3112 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=38f77718-2100-0000-b5f6-beeb280c0000 pid=3112 execve guuid=1f2ec118-2100-0000-b5f6-beeb290c0000 pid=3113 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=1f2ec118-2100-0000-b5f6-beeb290c0000 pid=3113 execve guuid=67f51f25-2100-0000-b5f6-beeb4e0c0000 pid=3150 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=67f51f25-2100-0000-b5f6-beeb4e0c0000 pid=3150 execve guuid=df6b7b25-2100-0000-b5f6-beeb520c0000 pid=3154 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=df6b7b25-2100-0000-b5f6-beeb520c0000 pid=3154 clone guuid=fdef1626-2100-0000-b5f6-beeb540c0000 pid=3156 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=fdef1626-2100-0000-b5f6-beeb540c0000 pid=3156 execve guuid=f6db5326-2100-0000-b5f6-beeb550c0000 pid=3157 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=f6db5326-2100-0000-b5f6-beeb550c0000 pid=3157 execve guuid=60431839-2100-0000-b5f6-beeb750c0000 pid=3189 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=60431839-2100-0000-b5f6-beeb750c0000 pid=3189 execve guuid=026a7939-2100-0000-b5f6-beeb760c0000 pid=3190 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=026a7939-2100-0000-b5f6-beeb760c0000 pid=3190 clone guuid=b378463a-2100-0000-b5f6-beeb780c0000 pid=3192 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=b378463a-2100-0000-b5f6-beeb780c0000 pid=3192 execve guuid=7ffbbd3a-2100-0000-b5f6-beeb790c0000 pid=3193 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=7ffbbd3a-2100-0000-b5f6-beeb790c0000 pid=3193 execve guuid=4e4b1047-2100-0000-b5f6-beeb7e0c0000 pid=3198 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=4e4b1047-2100-0000-b5f6-beeb7e0c0000 pid=3198 execve guuid=a0457247-2100-0000-b5f6-beeb800c0000 pid=3200 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=a0457247-2100-0000-b5f6-beeb800c0000 pid=3200 clone guuid=7b013248-2100-0000-b5f6-beeb840c0000 pid=3204 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=7b013248-2100-0000-b5f6-beeb840c0000 pid=3204 execve guuid=a5978648-2100-0000-b5f6-beeb860c0000 pid=3206 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=a5978648-2100-0000-b5f6-beeb860c0000 pid=3206 execve guuid=71ee7e58-2100-0000-b5f6-beeba30c0000 pid=3235 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=71ee7e58-2100-0000-b5f6-beeba30c0000 pid=3235 execve guuid=c3e80359-2100-0000-b5f6-beeba40c0000 pid=3236 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=c3e80359-2100-0000-b5f6-beeba40c0000 pid=3236 clone guuid=33d4ea5a-2100-0000-b5f6-beeba60c0000 pid=3238 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=33d4ea5a-2100-0000-b5f6-beeba60c0000 pid=3238 execve guuid=7d38785b-2100-0000-b5f6-beeba70c0000 pid=3239 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=7d38785b-2100-0000-b5f6-beeba70c0000 pid=3239 execve guuid=6d4a3c68-2100-0000-b5f6-beebaa0c0000 pid=3242 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=6d4a3c68-2100-0000-b5f6-beebaa0c0000 pid=3242 execve guuid=fcbf9568-2100-0000-b5f6-beebac0c0000 pid=3244 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=fcbf9568-2100-0000-b5f6-beebac0c0000 pid=3244 clone guuid=bbcbba69-2100-0000-b5f6-beebb10c0000 pid=3249 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=bbcbba69-2100-0000-b5f6-beebb10c0000 pid=3249 execve guuid=9918f969-2100-0000-b5f6-beebb30c0000 pid=3251 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=9918f969-2100-0000-b5f6-beebb30c0000 pid=3251 execve guuid=36fe8a75-2100-0000-b5f6-beebc20c0000 pid=3266 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=36fe8a75-2100-0000-b5f6-beebc20c0000 pid=3266 execve guuid=87dad875-2100-0000-b5f6-beebc30c0000 pid=3267 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=87dad875-2100-0000-b5f6-beebc30c0000 pid=3267 clone guuid=b4ba6d76-2100-0000-b5f6-beebc50c0000 pid=3269 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=b4ba6d76-2100-0000-b5f6-beebc50c0000 pid=3269 execve guuid=6851b476-2100-0000-b5f6-beebc60c0000 pid=3270 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=6851b476-2100-0000-b5f6-beebc60c0000 pid=3270 execve guuid=4c280783-2100-0000-b5f6-beebdc0c0000 pid=3292 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=4c280783-2100-0000-b5f6-beebdc0c0000 pid=3292 execve guuid=22385583-2100-0000-b5f6-beebdd0c0000 pid=3293 /tmp/vacron.exploit guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=22385583-2100-0000-b5f6-beebdd0c0000 pid=3293 execve guuid=540b7083-2100-0000-b5f6-beebdf0c0000 pid=3295 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=540b7083-2100-0000-b5f6-beebdf0c0000 pid=3295 execve guuid=90e1d483-2100-0000-b5f6-beebe10c0000 pid=3297 /usr/bin/wget net send-data write-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=90e1d483-2100-0000-b5f6-beebe10c0000 pid=3297 execve guuid=e2ec268f-2100-0000-b5f6-beebf60c0000 pid=3318 /usr/bin/chmod guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=e2ec268f-2100-0000-b5f6-beebf60c0000 pid=3318 execve guuid=3cff7b8f-2100-0000-b5f6-beebf70c0000 pid=3319 /usr/bin/dash guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=3cff7b8f-2100-0000-b5f6-beebf70c0000 pid=3319 clone guuid=04bcfe90-2100-0000-b5f6-beebfa0c0000 pid=3322 /usr/bin/rm delete-file guuid=f52f9af2-2000-0000-b5f6-beebbc0b0000 pid=3004->guuid=04bcfe90-2100-0000-b5f6-beebfa0c0000 pid=3322 execve ce2040a6-1382-57a9-8f72-87c510446939 91.92.241.8:80 guuid=5a11eff2-2000-0000-b5f6-beebbe0b0000 pid=3006->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=6f05f607-2100-0000-b5f6-beebfd0b0000 pid=3069->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=1f2ec118-2100-0000-b5f6-beeb290c0000 pid=3113->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=f6db5326-2100-0000-b5f6-beeb550c0000 pid=3157->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=7ffbbd3a-2100-0000-b5f6-beeb790c0000 pid=3193->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=a5978648-2100-0000-b5f6-beeb860c0000 pid=3206->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=7d38785b-2100-0000-b5f6-beeba70c0000 pid=3239->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=9918f969-2100-0000-b5f6-beebb30c0000 pid=3251->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=6851b476-2100-0000-b5f6-beebc60c0000 pid=3270->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=07f36683-2100-0000-b5f6-beebde0c0000 pid=3294 /tmp/vacron.exploit zombie guuid=22385583-2100-0000-b5f6-beebdd0c0000 pid=3293->guuid=07f36683-2100-0000-b5f6-beebde0c0000 pid=3294 clone guuid=ec827283-2100-0000-b5f6-beebe00c0000 pid=3296 /tmp/vacron.exploit dns net send-data zombie guuid=07f36683-2100-0000-b5f6-beebde0c0000 pid=3294->guuid=ec827283-2100-0000-b5f6-beebe00c0000 pid=3296 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ec827283-2100-0000-b5f6-beebe00c0000 pid=3296->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 35B 3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 auth.binaries.lol:41323 guuid=ec827283-2100-0000-b5f6-beebe00c0000 pid=3296->3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 send: 11B guuid=71de04ce-2100-0000-b5f6-beeb7e0d0000 pid=3454 /tmp/vacron.exploit net net-scan send-data guuid=ec827283-2100-0000-b5f6-beebe00c0000 pid=3296->guuid=71de04ce-2100-0000-b5f6-beeb7e0d0000 pid=3454 clone guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455 /tmp/vacron.exploit net net-scan send-data guuid=ec827283-2100-0000-b5f6-beebe00c0000 pid=3296->guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455 clone 5747732c-f603-51c6-9252-e264289619bd auth.binaries.lol:80 guuid=90e1d483-2100-0000-b5f6-beebe10c0000 pid=3297->5747732c-f603-51c6-9252-e264289619bd send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=71de04ce-2100-0000-b5f6-beeb7e0d0000 pid=3454->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=71de04ce-2100-0000-b5f6-beeb7e0d0000 pid=3454|send-data send-data to 4097 IP addresses review logs to see them all guuid=71de04ce-2100-0000-b5f6-beeb7e0d0000 pid=3454->guuid=71de04ce-2100-0000-b5f6-beeb7e0d0000 pid=3454|send-data send guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 1b6340c5-8356-5f4c-9411-280555026a10 46.166.172.163:37215 guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455->1b6340c5-8356-5f4c-9411-280555026a10 send: 40B guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455|send-data send-data to 4096 IP addresses review logs to see them all guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455->guuid=803e12ce-2100-0000-b5f6-beeb7f0d0000 pid=3455|send-data send
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-10-19 21:10:17 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 20f5bac38fd073fe3b46916e783f8cfa09556ae0ab9a5968de747df33f7cf077

(this sample)

  
Delivery method
Distributed via web download

Comments