MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2159eb49f5b01cc80af86541ed39c156a7b96e0e6b3ba551b221e4f543c4ecfd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2159eb49f5b01cc80af86541ed39c156a7b96e0e6b3ba551b221e4f543c4ecfd
SHA3-384 hash: 440317a761493c0aa5329d258b0a37f843094fcfffa819733309ee842d1cfeb28ac3136b6f805bf7bab68240bda5e6c9
SHA1 hash: 9884edd2971923ef1ea5d7e6e3a9c0a26fdfdcc9
MD5 hash: a4d8d2dba180f0e00dda2046c2b32d59
humanhash: football-muppet-ten-berlin
File name:telnet.sh
Download: download sample
File size:1'694 bytes
First seen:2025-08-30 11:23:49 UTC
Last seen:2025-08-30 17:11:12 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:j50vAFSdJ8JYlGTzw3ol+rZZmNMVp05Ide:ujI
TLSH T1793186CD13E09ED2C746DEA1B872C3C4B28DD58A26A2CB75B4CB1C21485DAC1BC55726
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.248.150.68/x86_64n/an/aelf ua-wget
http://87.248.150.68/aarch64n/an/aelf ua-wget
http://87.248.150.68/m68kn/an/aelf ua-wget
http://87.248.150.68/mipsn/an/aelf ua-wget
http://87.248.150.68/mipseln/an/aelf ua-wget
http://87.248.150.68/powerpcn/an/aelf ua-wget
http://87.248.150.68/sparcn/an/aelf ua-wget
http://87.248.150.68/sh4n/an/aelf ua-wget
http://87.248.150.68/arcn/an/aelf ua-wget
http://87.248.150.68/i486n/an/aelf ua-wget
http://87.248.150.68/armv4ln/an/aelf ua-wget
http://87.248.150.68/armv5ln/an/aelf ua-wget
http://87.248.150.68/armv6ln/an/aelf ua-wget
http://87.248.150.68/armv7ln/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=a0899651-1900-0000-f0f6-4df016110000 pid=4374 /usr/bin/sudo guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385 /tmp/sample.bin guuid=a0899651-1900-0000-f0f6-4df016110000 pid=4374->guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385 execve guuid=3b0efd53-1900-0000-f0f6-4df022110000 pid=4386 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=3b0efd53-1900-0000-f0f6-4df022110000 pid=4386 execve guuid=4ec6d05f-1900-0000-f0f6-4df04f110000 pid=4431 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=4ec6d05f-1900-0000-f0f6-4df04f110000 pid=4431 execve guuid=aab24b70-1900-0000-f0f6-4df088110000 pid=4488 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=aab24b70-1900-0000-f0f6-4df088110000 pid=4488 execve guuid=541d8470-1900-0000-f0f6-4df08a110000 pid=4490 /home/sandbox/x86_64 guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=541d8470-1900-0000-f0f6-4df08a110000 pid=4490 execve guuid=e157b770-1900-0000-f0f6-4df08b110000 pid=4491 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=e157b770-1900-0000-f0f6-4df08b110000 pid=4491 execve guuid=a9690a7c-1900-0000-f0f6-4df0ba110000 pid=4538 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=a9690a7c-1900-0000-f0f6-4df0ba110000 pid=4538 execve guuid=70b49d8c-1900-0000-f0f6-4df003120000 pid=4611 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=70b49d8c-1900-0000-f0f6-4df003120000 pid=4611 execve guuid=d604f28c-1900-0000-f0f6-4df005120000 pid=4613 /home/sandbox/aarch64 guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=d604f28c-1900-0000-f0f6-4df005120000 pid=4613 execve guuid=b494488d-1900-0000-f0f6-4df006120000 pid=4614 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=b494488d-1900-0000-f0f6-4df006120000 pid=4614 execve guuid=a8cb4097-1900-0000-f0f6-4df027120000 pid=4647 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=a8cb4097-1900-0000-f0f6-4df027120000 pid=4647 execve guuid=97781fa5-1900-0000-f0f6-4df056120000 pid=4694 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=97781fa5-1900-0000-f0f6-4df056120000 pid=4694 execve guuid=833388a5-1900-0000-f0f6-4df058120000 pid=4696 /home/sandbox/m68k guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=833388a5-1900-0000-f0f6-4df058120000 pid=4696 execve guuid=e2fce5a5-1900-0000-f0f6-4df059120000 pid=4697 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=e2fce5a5-1900-0000-f0f6-4df059120000 pid=4697 execve guuid=ccf1cbaf-1900-0000-f0f6-4df07d120000 pid=4733 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=ccf1cbaf-1900-0000-f0f6-4df07d120000 pid=4733 execve guuid=5732daba-1900-0000-f0f6-4df097120000 pid=4759 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=5732daba-1900-0000-f0f6-4df097120000 pid=4759 execve guuid=d2311fbb-1900-0000-f0f6-4df098120000 pid=4760 /home/sandbox/mips guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=d2311fbb-1900-0000-f0f6-4df098120000 pid=4760 execve guuid=1b2a55bb-1900-0000-f0f6-4df09a120000 pid=4762 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=1b2a55bb-1900-0000-f0f6-4df09a120000 pid=4762 execve guuid=eae0c9c6-1900-0000-f0f6-4df0b8120000 pid=4792 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=eae0c9c6-1900-0000-f0f6-4df0b8120000 pid=4792 execve guuid=caf2c1d5-1900-0000-f0f6-4df0e1120000 pid=4833 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=caf2c1d5-1900-0000-f0f6-4df0e1120000 pid=4833 execve guuid=4f0e08d6-1900-0000-f0f6-4df0e3120000 pid=4835 /home/sandbox/mipsel guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=4f0e08d6-1900-0000-f0f6-4df0e3120000 pid=4835 execve guuid=deae46d6-1900-0000-f0f6-4df0e4120000 pid=4836 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=deae46d6-1900-0000-f0f6-4df0e4120000 pid=4836 execve guuid=12ba05e2-1900-0000-f0f6-4df008130000 pid=4872 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=12ba05e2-1900-0000-f0f6-4df008130000 pid=4872 execve guuid=0cecc345-1a00-0000-f0f6-4df0a4130000 pid=5028 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=0cecc345-1a00-0000-f0f6-4df0a4130000 pid=5028 execve guuid=7b124546-1a00-0000-f0f6-4df0a8130000 pid=5032 /home/sandbox/powerpc guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=7b124546-1a00-0000-f0f6-4df0a8130000 pid=5032 execve guuid=77b2bb46-1a00-0000-f0f6-4df0a9130000 pid=5033 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=77b2bb46-1a00-0000-f0f6-4df0a9130000 pid=5033 execve guuid=b8d68553-1a00-0000-f0f6-4df0ca130000 pid=5066 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=b8d68553-1a00-0000-f0f6-4df0ca130000 pid=5066 execve guuid=f619d260-1a00-0000-f0f6-4df0f6130000 pid=5110 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=f619d260-1a00-0000-f0f6-4df0f6130000 pid=5110 execve guuid=a2f87061-1a00-0000-f0f6-4df0f7130000 pid=5111 /home/sandbox/sparc guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=a2f87061-1a00-0000-f0f6-4df0f7130000 pid=5111 execve guuid=45effc61-1a00-0000-f0f6-4df0f9130000 pid=5113 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=45effc61-1a00-0000-f0f6-4df0f9130000 pid=5113 execve guuid=52375d6d-1a00-0000-f0f6-4df00e140000 pid=5134 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=52375d6d-1a00-0000-f0f6-4df00e140000 pid=5134 execve guuid=4e40567b-1a00-0000-f0f6-4df030140000 pid=5168 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=4e40567b-1a00-0000-f0f6-4df030140000 pid=5168 execve guuid=49eda27b-1a00-0000-f0f6-4df031140000 pid=5169 /home/sandbox/sh4 guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=49eda27b-1a00-0000-f0f6-4df031140000 pid=5169 execve guuid=fe2ddb7b-1a00-0000-f0f6-4df033140000 pid=5171 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=fe2ddb7b-1a00-0000-f0f6-4df033140000 pid=5171 execve guuid=f1730486-1a00-0000-f0f6-4df057140000 pid=5207 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=f1730486-1a00-0000-f0f6-4df057140000 pid=5207 execve guuid=d25aeb92-1a00-0000-f0f6-4df07d140000 pid=5245 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=d25aeb92-1a00-0000-f0f6-4df07d140000 pid=5245 execve guuid=0c863793-1a00-0000-f0f6-4df07e140000 pid=5246 /home/sandbox/arc guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=0c863793-1a00-0000-f0f6-4df07e140000 pid=5246 execve guuid=ce586f93-1a00-0000-f0f6-4df07f140000 pid=5247 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=ce586f93-1a00-0000-f0f6-4df07f140000 pid=5247 execve guuid=2c45f49e-1a00-0000-f0f6-4df080140000 pid=5248 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=2c45f49e-1a00-0000-f0f6-4df080140000 pid=5248 execve guuid=7deb5ab0-1a00-0000-f0f6-4df084140000 pid=5252 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=7deb5ab0-1a00-0000-f0f6-4df084140000 pid=5252 execve guuid=d75ca2b0-1a00-0000-f0f6-4df085140000 pid=5253 /home/sandbox/i486 guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=d75ca2b0-1a00-0000-f0f6-4df085140000 pid=5253 execve guuid=eb2601b1-1a00-0000-f0f6-4df086140000 pid=5254 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=eb2601b1-1a00-0000-f0f6-4df086140000 pid=5254 execve guuid=ef6824bd-1a00-0000-f0f6-4df08f140000 pid=5263 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=ef6824bd-1a00-0000-f0f6-4df08f140000 pid=5263 execve guuid=b17379c8-1a00-0000-f0f6-4df090140000 pid=5264 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=b17379c8-1a00-0000-f0f6-4df090140000 pid=5264 execve guuid=2b0ebfc8-1a00-0000-f0f6-4df091140000 pid=5265 /home/sandbox/armv4l guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=2b0ebfc8-1a00-0000-f0f6-4df091140000 pid=5265 execve guuid=b68ffbc8-1a00-0000-f0f6-4df092140000 pid=5266 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=b68ffbc8-1a00-0000-f0f6-4df092140000 pid=5266 execve guuid=d1e301d4-1a00-0000-f0f6-4df093140000 pid=5267 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=d1e301d4-1a00-0000-f0f6-4df093140000 pid=5267 execve guuid=3b0518e0-1a00-0000-f0f6-4df094140000 pid=5268 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=3b0518e0-1a00-0000-f0f6-4df094140000 pid=5268 execve guuid=762960e0-1a00-0000-f0f6-4df095140000 pid=5269 /home/sandbox/armv5l guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=762960e0-1a00-0000-f0f6-4df095140000 pid=5269 execve guuid=5b40a0e0-1a00-0000-f0f6-4df096140000 pid=5270 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=5b40a0e0-1a00-0000-f0f6-4df096140000 pid=5270 execve guuid=6077cbec-1a00-0000-f0f6-4df097140000 pid=5271 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=6077cbec-1a00-0000-f0f6-4df097140000 pid=5271 execve guuid=ea4d7cfa-1a00-0000-f0f6-4df098140000 pid=5272 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=ea4d7cfa-1a00-0000-f0f6-4df098140000 pid=5272 execve guuid=eca7d0fa-1a00-0000-f0f6-4df099140000 pid=5273 /home/sandbox/armv6l guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=eca7d0fa-1a00-0000-f0f6-4df099140000 pid=5273 execve guuid=66b011fb-1a00-0000-f0f6-4df09a140000 pid=5274 /usr/bin/wget net send-data guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=66b011fb-1a00-0000-f0f6-4df09a140000 pid=5274 execve guuid=1f16af06-1b00-0000-f0f6-4df09b140000 pid=5275 /usr/bin/curl net send-data write-file guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=1f16af06-1b00-0000-f0f6-4df09b140000 pid=5275 execve guuid=74407813-1b00-0000-f0f6-4df09c140000 pid=5276 /usr/bin/chmod guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=74407813-1b00-0000-f0f6-4df09c140000 pid=5276 execve guuid=36022c14-1b00-0000-f0f6-4df09d140000 pid=5277 /home/sandbox/armv7l guuid=804b8753-1900-0000-f0f6-4df021110000 pid=4385->guuid=36022c14-1b00-0000-f0f6-4df09d140000 pid=5277 execve bf95abf9-e4f4-5b43-97fa-c007e1700665 87.248.150.68:80 guuid=3b0efd53-1900-0000-f0f6-4df022110000 pid=4386->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 134B guuid=4ec6d05f-1900-0000-f0f6-4df04f110000 pid=4431->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 83B guuid=e157b770-1900-0000-f0f6-4df08b110000 pid=4491->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 135B guuid=a9690a7c-1900-0000-f0f6-4df0ba110000 pid=4538->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 84B guuid=b494488d-1900-0000-f0f6-4df006120000 pid=4614->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 132B guuid=a8cb4097-1900-0000-f0f6-4df027120000 pid=4647->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 81B guuid=e2fce5a5-1900-0000-f0f6-4df059120000 pid=4697->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 132B guuid=ccf1cbaf-1900-0000-f0f6-4df07d120000 pid=4733->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 81B guuid=1b2a55bb-1900-0000-f0f6-4df09a120000 pid=4762->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 134B guuid=eae0c9c6-1900-0000-f0f6-4df0b8120000 pid=4792->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 83B guuid=deae46d6-1900-0000-f0f6-4df0e4120000 pid=4836->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 135B guuid=12ba05e2-1900-0000-f0f6-4df008130000 pid=4872->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 84B guuid=77b2bb46-1a00-0000-f0f6-4df0a9130000 pid=5033->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 133B guuid=b8d68553-1a00-0000-f0f6-4df0ca130000 pid=5066->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 82B guuid=45effc61-1a00-0000-f0f6-4df0f9130000 pid=5113->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 131B guuid=52375d6d-1a00-0000-f0f6-4df00e140000 pid=5134->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 80B guuid=fe2ddb7b-1a00-0000-f0f6-4df033140000 pid=5171->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 131B guuid=f1730486-1a00-0000-f0f6-4df057140000 pid=5207->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 80B guuid=ce586f93-1a00-0000-f0f6-4df07f140000 pid=5247->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 132B guuid=2c45f49e-1a00-0000-f0f6-4df080140000 pid=5248->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 81B guuid=eb2601b1-1a00-0000-f0f6-4df086140000 pid=5254->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 134B guuid=ef6824bd-1a00-0000-f0f6-4df08f140000 pid=5263->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 83B guuid=b68ffbc8-1a00-0000-f0f6-4df092140000 pid=5266->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 134B guuid=d1e301d4-1a00-0000-f0f6-4df093140000 pid=5267->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 83B guuid=5b40a0e0-1a00-0000-f0f6-4df096140000 pid=5270->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 134B guuid=6077cbec-1a00-0000-f0f6-4df097140000 pid=5271->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 83B guuid=66b011fb-1a00-0000-f0f6-4df09a140000 pid=5274->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 134B guuid=1f16af06-1b00-0000-f0f6-4df09b140000 pid=5275->bf95abf9-e4f4-5b43-97fa-c007e1700665 send: 83B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-30 11:24:45 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2159eb49f5b01cc80af86541ed39c156a7b96e0e6b3ba551b221e4f543c4ecfd

(this sample)

  
Delivery method
Distributed via web download

Comments