MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 290887c66356b0d17dbd3752b1ec1ffb8f7585d4f09f8531b5a59abbf294e84f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 290887c66356b0d17dbd3752b1ec1ffb8f7585d4f09f8531b5a59abbf294e84f
SHA3-384 hash: 9725cd8999f7b1bfe2bb6bb11171fd56159d13772267485a56123c36240e09955be8ab3bc0c761201ec61fe743d1c65e
SHA1 hash: fb4db3e464dff0dcaf719fe40fcededa4ab9cb5e
MD5 hash: e8046912641e239eb89e8c54ffb19b84
humanhash: don-burger-kentucky-virginia
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-19 06:32:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UZ56ZrXNh6nEajDNo6NID5Pdr6PCwM6scaBfUF6fUouzaG/6txT6J557NIr6gSw+:c0zMEajQD4ChlCaBy5YlvfgCjruFRNN
TLSH T1C03152EE10102E365713CAEE7BA23949F00C91E7399BC7E4C9580EE882985ED7355BC5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/b724e9n/an/aelf ua-wget
http://5.182.210.61/fae366n/an/aelf ua-wget
http://5.182.210.61/d26a3fn/an/aelf ua-wget
http://5.182.210.61/235023n/an/aelf ua-wget
http://5.182.210.61/14f32dn/an/aelf ua-wget
http://5.182.210.61/7e1be0n/an/aelf ua-wget
http://5.182.210.61/01abd5n/an/aelf ua-wget
http://5.182.210.61/b05475n/an/aelf ua-wget
http://5.182.210.61/a43aden/an/aelf ua-wget
http://5.182.210.61/d26e3dn/an/aelf ua-wget
http://5.182.210.61/9b4ad6n/an/aelf ua-wget
http://5.182.210.61/41dc78n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=cb0bbff8-1d00-0000-fec1-75a835140000 pid=5173 /usr/bin/sudo guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174 /tmp/sample.bin guuid=cb0bbff8-1d00-0000-fec1-75a835140000 pid=5173->guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174 execve guuid=68aa60fd-1d00-0000-fec1-75a837140000 pid=5175 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=68aa60fd-1d00-0000-fec1-75a837140000 pid=5175 execve guuid=0d8eab22-1e00-0000-fec1-75a838140000 pid=5176 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=0d8eab22-1e00-0000-fec1-75a838140000 pid=5176 execve guuid=9f2e0e33-1e00-0000-fec1-75a839140000 pid=5177 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=9f2e0e33-1e00-0000-fec1-75a839140000 pid=5177 execve guuid=a4f3ba38-1e00-0000-fec1-75a83a140000 pid=5178 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=a4f3ba38-1e00-0000-fec1-75a83a140000 pid=5178 clone guuid=7a427943-1e00-0000-fec1-75a83c140000 pid=5180 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=7a427943-1e00-0000-fec1-75a83c140000 pid=5180 execve guuid=5baba444-1e00-0000-fec1-75a83d140000 pid=5181 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=5baba444-1e00-0000-fec1-75a83d140000 pid=5181 execve guuid=8c7c0445-1e00-0000-fec1-75a83e140000 pid=5182 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=8c7c0445-1e00-0000-fec1-75a83e140000 pid=5182 execve guuid=172e5948-1e00-0000-fec1-75a83f140000 pid=5183 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=172e5948-1e00-0000-fec1-75a83f140000 pid=5183 execve guuid=071b984e-1e00-0000-fec1-75a840140000 pid=5184 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=071b984e-1e00-0000-fec1-75a840140000 pid=5184 execve guuid=18f3fd4e-1e00-0000-fec1-75a841140000 pid=5185 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=18f3fd4e-1e00-0000-fec1-75a841140000 pid=5185 clone guuid=2c6d554f-1e00-0000-fec1-75a843140000 pid=5187 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=2c6d554f-1e00-0000-fec1-75a843140000 pid=5187 execve guuid=e7aa4550-1e00-0000-fec1-75a844140000 pid=5188 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=e7aa4550-1e00-0000-fec1-75a844140000 pid=5188 execve guuid=e0903551-1e00-0000-fec1-75a845140000 pid=5189 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=e0903551-1e00-0000-fec1-75a845140000 pid=5189 execve guuid=06121656-1e00-0000-fec1-75a846140000 pid=5190 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=06121656-1e00-0000-fec1-75a846140000 pid=5190 execve guuid=4b91185b-1e00-0000-fec1-75a847140000 pid=5191 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=4b91185b-1e00-0000-fec1-75a847140000 pid=5191 execve guuid=dd385c5c-1e00-0000-fec1-75a848140000 pid=5192 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=dd385c5c-1e00-0000-fec1-75a848140000 pid=5192 clone guuid=2387c45c-1e00-0000-fec1-75a84a140000 pid=5194 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=2387c45c-1e00-0000-fec1-75a84a140000 pid=5194 execve guuid=24aa4d5d-1e00-0000-fec1-75a84b140000 pid=5195 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=24aa4d5d-1e00-0000-fec1-75a84b140000 pid=5195 execve guuid=dea7d95d-1e00-0000-fec1-75a84c140000 pid=5196 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=dea7d95d-1e00-0000-fec1-75a84c140000 pid=5196 execve guuid=2dcc6361-1e00-0000-fec1-75a84d140000 pid=5197 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=2dcc6361-1e00-0000-fec1-75a84d140000 pid=5197 execve guuid=f2e9a567-1e00-0000-fec1-75a84e140000 pid=5198 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=f2e9a567-1e00-0000-fec1-75a84e140000 pid=5198 execve guuid=a848de68-1e00-0000-fec1-75a84f140000 pid=5199 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=a848de68-1e00-0000-fec1-75a84f140000 pid=5199 clone guuid=bc5e2969-1e00-0000-fec1-75a851140000 pid=5201 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=bc5e2969-1e00-0000-fec1-75a851140000 pid=5201 execve guuid=c728b269-1e00-0000-fec1-75a852140000 pid=5202 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=c728b269-1e00-0000-fec1-75a852140000 pid=5202 execve guuid=cf5e046a-1e00-0000-fec1-75a853140000 pid=5203 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=cf5e046a-1e00-0000-fec1-75a853140000 pid=5203 execve guuid=51745c6d-1e00-0000-fec1-75a854140000 pid=5204 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=51745c6d-1e00-0000-fec1-75a854140000 pid=5204 execve guuid=841b0e75-1e00-0000-fec1-75a855140000 pid=5205 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=841b0e75-1e00-0000-fec1-75a855140000 pid=5205 execve guuid=a5e07f75-1e00-0000-fec1-75a856140000 pid=5206 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=a5e07f75-1e00-0000-fec1-75a856140000 pid=5206 clone guuid=1fdcf477-1e00-0000-fec1-75a858140000 pid=5208 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=1fdcf477-1e00-0000-fec1-75a858140000 pid=5208 execve guuid=a9a2327c-1e00-0000-fec1-75a859140000 pid=5209 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=a9a2327c-1e00-0000-fec1-75a859140000 pid=5209 execve guuid=3b816d80-1e00-0000-fec1-75a85a140000 pid=5210 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=3b816d80-1e00-0000-fec1-75a85a140000 pid=5210 execve guuid=045a4084-1e00-0000-fec1-75a85b140000 pid=5211 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=045a4084-1e00-0000-fec1-75a85b140000 pid=5211 execve guuid=b493738b-1e00-0000-fec1-75a85c140000 pid=5212 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=b493738b-1e00-0000-fec1-75a85c140000 pid=5212 execve guuid=73deb98b-1e00-0000-fec1-75a85d140000 pid=5213 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=73deb98b-1e00-0000-fec1-75a85d140000 pid=5213 clone guuid=c141168c-1e00-0000-fec1-75a85f140000 pid=5215 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=c141168c-1e00-0000-fec1-75a85f140000 pid=5215 execve guuid=fab5698c-1e00-0000-fec1-75a860140000 pid=5216 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=fab5698c-1e00-0000-fec1-75a860140000 pid=5216 execve guuid=59efbd90-1e00-0000-fec1-75a861140000 pid=5217 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=59efbd90-1e00-0000-fec1-75a861140000 pid=5217 execve guuid=b1e16c93-1e00-0000-fec1-75a862140000 pid=5218 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=b1e16c93-1e00-0000-fec1-75a862140000 pid=5218 execve guuid=8bcc0b9b-1e00-0000-fec1-75a863140000 pid=5219 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=8bcc0b9b-1e00-0000-fec1-75a863140000 pid=5219 execve guuid=af78629b-1e00-0000-fec1-75a864140000 pid=5220 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=af78629b-1e00-0000-fec1-75a864140000 pid=5220 clone guuid=a27d669c-1e00-0000-fec1-75a866140000 pid=5222 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=a27d669c-1e00-0000-fec1-75a866140000 pid=5222 execve guuid=8ca6df9c-1e00-0000-fec1-75a867140000 pid=5223 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=8ca6df9c-1e00-0000-fec1-75a867140000 pid=5223 execve guuid=8eb1939d-1e00-0000-fec1-75a868140000 pid=5224 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=8eb1939d-1e00-0000-fec1-75a868140000 pid=5224 execve guuid=bb8163a1-1e00-0000-fec1-75a869140000 pid=5225 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=bb8163a1-1e00-0000-fec1-75a869140000 pid=5225 execve guuid=862965a6-1e00-0000-fec1-75a86a140000 pid=5226 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=862965a6-1e00-0000-fec1-75a86a140000 pid=5226 execve guuid=752adca6-1e00-0000-fec1-75a86b140000 pid=5227 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=752adca6-1e00-0000-fec1-75a86b140000 pid=5227 clone guuid=b70666a7-1e00-0000-fec1-75a86d140000 pid=5229 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=b70666a7-1e00-0000-fec1-75a86d140000 pid=5229 execve guuid=189167a8-1e00-0000-fec1-75a86e140000 pid=5230 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=189167a8-1e00-0000-fec1-75a86e140000 pid=5230 execve guuid=504d1ea9-1e00-0000-fec1-75a86f140000 pid=5231 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=504d1ea9-1e00-0000-fec1-75a86f140000 pid=5231 execve guuid=c65d44ad-1e00-0000-fec1-75a870140000 pid=5232 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=c65d44ad-1e00-0000-fec1-75a870140000 pid=5232 execve guuid=3de6d9b3-1e00-0000-fec1-75a871140000 pid=5233 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=3de6d9b3-1e00-0000-fec1-75a871140000 pid=5233 execve guuid=7dff1eb4-1e00-0000-fec1-75a872140000 pid=5234 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=7dff1eb4-1e00-0000-fec1-75a872140000 pid=5234 clone guuid=6c6351b4-1e00-0000-fec1-75a874140000 pid=5236 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=6c6351b4-1e00-0000-fec1-75a874140000 pid=5236 execve guuid=904991b4-1e00-0000-fec1-75a875140000 pid=5237 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=904991b4-1e00-0000-fec1-75a875140000 pid=5237 execve guuid=b5dfeab4-1e00-0000-fec1-75a876140000 pid=5238 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=b5dfeab4-1e00-0000-fec1-75a876140000 pid=5238 execve guuid=9c397eb8-1e00-0000-fec1-75a877140000 pid=5239 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=9c397eb8-1e00-0000-fec1-75a877140000 pid=5239 execve guuid=e3f18fbd-1e00-0000-fec1-75a878140000 pid=5240 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=e3f18fbd-1e00-0000-fec1-75a878140000 pid=5240 execve guuid=893eecbd-1e00-0000-fec1-75a879140000 pid=5241 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=893eecbd-1e00-0000-fec1-75a879140000 pid=5241 clone guuid=918935be-1e00-0000-fec1-75a87b140000 pid=5243 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=918935be-1e00-0000-fec1-75a87b140000 pid=5243 execve guuid=7f2b8abe-1e00-0000-fec1-75a87c140000 pid=5244 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=7f2b8abe-1e00-0000-fec1-75a87c140000 pid=5244 execve guuid=4fdfd1be-1e00-0000-fec1-75a87d140000 pid=5245 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=4fdfd1be-1e00-0000-fec1-75a87d140000 pid=5245 execve guuid=7cfe66c1-1e00-0000-fec1-75a87e140000 pid=5246 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=7cfe66c1-1e00-0000-fec1-75a87e140000 pid=5246 execve guuid=eed6d5c4-1e00-0000-fec1-75a87f140000 pid=5247 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=eed6d5c4-1e00-0000-fec1-75a87f140000 pid=5247 execve guuid=2a5c20c5-1e00-0000-fec1-75a880140000 pid=5248 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=2a5c20c5-1e00-0000-fec1-75a880140000 pid=5248 clone guuid=782558c5-1e00-0000-fec1-75a882140000 pid=5250 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=782558c5-1e00-0000-fec1-75a882140000 pid=5250 execve guuid=0285a1c5-1e00-0000-fec1-75a883140000 pid=5251 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=0285a1c5-1e00-0000-fec1-75a883140000 pid=5251 execve guuid=0d84e6c5-1e00-0000-fec1-75a884140000 pid=5252 /usr/bin/wget net send-data guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=0d84e6c5-1e00-0000-fec1-75a884140000 pid=5252 execve guuid=ce6b6fc8-1e00-0000-fec1-75a885140000 pid=5253 /usr/bin/curl net send-data write-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=ce6b6fc8-1e00-0000-fec1-75a885140000 pid=5253 execve guuid=b755fccb-1e00-0000-fec1-75a886140000 pid=5254 /usr/bin/chmod guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=b755fccb-1e00-0000-fec1-75a886140000 pid=5254 execve guuid=b8f247cc-1e00-0000-fec1-75a887140000 pid=5255 /usr/bin/bash guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=b8f247cc-1e00-0000-fec1-75a887140000 pid=5255 clone guuid=11d184cc-1e00-0000-fec1-75a889140000 pid=5257 /usr/bin/rm delete-file guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=11d184cc-1e00-0000-fec1-75a889140000 pid=5257 execve guuid=c1cdd2cc-1e00-0000-fec1-75a88a140000 pid=5258 /usr/bin/rm guuid=4bea1dfc-1d00-0000-fec1-75a836140000 pid=5174->guuid=c1cdd2cc-1e00-0000-fec1-75a88a140000 pid=5258 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=68aa60fd-1d00-0000-fec1-75a837140000 pid=5175->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=0d8eab22-1e00-0000-fec1-75a838140000 pid=5176->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=679eaf3e-1e00-0000-fec1-75a83b140000 pid=5179 /usr/bin/bash guuid=a4f3ba38-1e00-0000-fec1-75a83a140000 pid=5178->guuid=679eaf3e-1e00-0000-fec1-75a83b140000 pid=5179 clone guuid=8c7c0445-1e00-0000-fec1-75a83e140000 pid=5182->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=172e5948-1e00-0000-fec1-75a83f140000 pid=5183->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e4591f4f-1e00-0000-fec1-75a842140000 pid=5186 /usr/bin/bash guuid=18f3fd4e-1e00-0000-fec1-75a841140000 pid=5185->guuid=e4591f4f-1e00-0000-fec1-75a842140000 pid=5186 clone guuid=e0903551-1e00-0000-fec1-75a845140000 pid=5189->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=06121656-1e00-0000-fec1-75a846140000 pid=5190->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0223835c-1e00-0000-fec1-75a849140000 pid=5193 /usr/bin/bash guuid=dd385c5c-1e00-0000-fec1-75a848140000 pid=5192->guuid=0223835c-1e00-0000-fec1-75a849140000 pid=5193 clone guuid=dea7d95d-1e00-0000-fec1-75a84c140000 pid=5196->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=2dcc6361-1e00-0000-fec1-75a84d140000 pid=5197->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=d9a2f968-1e00-0000-fec1-75a850140000 pid=5200 /usr/bin/bash guuid=a848de68-1e00-0000-fec1-75a84f140000 pid=5199->guuid=d9a2f968-1e00-0000-fec1-75a850140000 pid=5200 clone guuid=cf5e046a-1e00-0000-fec1-75a853140000 pid=5203->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=51745c6d-1e00-0000-fec1-75a854140000 pid=5204->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ae889875-1e00-0000-fec1-75a857140000 pid=5207 /usr/bin/bash guuid=a5e07f75-1e00-0000-fec1-75a856140000 pid=5206->guuid=ae889875-1e00-0000-fec1-75a857140000 pid=5207 clone guuid=3b816d80-1e00-0000-fec1-75a85a140000 pid=5210->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=045a4084-1e00-0000-fec1-75a85b140000 pid=5211->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e086fc8b-1e00-0000-fec1-75a85e140000 pid=5214 /usr/bin/bash guuid=73deb98b-1e00-0000-fec1-75a85d140000 pid=5213->guuid=e086fc8b-1e00-0000-fec1-75a85e140000 pid=5214 clone guuid=59efbd90-1e00-0000-fec1-75a861140000 pid=5217->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=b1e16c93-1e00-0000-fec1-75a862140000 pid=5218->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=2433fe9b-1e00-0000-fec1-75a865140000 pid=5221 /usr/bin/bash guuid=af78629b-1e00-0000-fec1-75a864140000 pid=5220->guuid=2433fe9b-1e00-0000-fec1-75a865140000 pid=5221 clone guuid=8eb1939d-1e00-0000-fec1-75a868140000 pid=5224->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=bb8163a1-1e00-0000-fec1-75a869140000 pid=5225->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=f3c031a7-1e00-0000-fec1-75a86c140000 pid=5228 /usr/bin/bash guuid=752adca6-1e00-0000-fec1-75a86b140000 pid=5227->guuid=f3c031a7-1e00-0000-fec1-75a86c140000 pid=5228 clone guuid=504d1ea9-1e00-0000-fec1-75a86f140000 pid=5231->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=c65d44ad-1e00-0000-fec1-75a870140000 pid=5232->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=a29533b4-1e00-0000-fec1-75a873140000 pid=5235 /usr/bin/bash guuid=7dff1eb4-1e00-0000-fec1-75a872140000 pid=5234->guuid=a29533b4-1e00-0000-fec1-75a873140000 pid=5235 clone guuid=b5dfeab4-1e00-0000-fec1-75a876140000 pid=5238->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=9c397eb8-1e00-0000-fec1-75a877140000 pid=5239->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=bd980abe-1e00-0000-fec1-75a87a140000 pid=5242 /usr/bin/bash guuid=893eecbd-1e00-0000-fec1-75a879140000 pid=5241->guuid=bd980abe-1e00-0000-fec1-75a87a140000 pid=5242 clone guuid=4fdfd1be-1e00-0000-fec1-75a87d140000 pid=5245->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=7cfe66c1-1e00-0000-fec1-75a87e140000 pid=5246->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=a01437c5-1e00-0000-fec1-75a881140000 pid=5249 /usr/bin/bash guuid=2a5c20c5-1e00-0000-fec1-75a880140000 pid=5248->guuid=a01437c5-1e00-0000-fec1-75a881140000 pid=5249 clone guuid=0d84e6c5-1e00-0000-fec1-75a884140000 pid=5252->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=ce6b6fc8-1e00-0000-fec1-75a885140000 pid=5253->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e9195fcc-1e00-0000-fec1-75a888140000 pid=5256 /usr/bin/bash guuid=b8f247cc-1e00-0000-fec1-75a887140000 pid=5255->guuid=e9195fcc-1e00-0000-fec1-75a888140000 pid=5256 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-19 06:32:32 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 290887c66356b0d17dbd3752b1ec1ffb8f7585d4f09f8531b5a59abbf294e84f

(this sample)

  
Delivery method
Distributed via web download

Comments