MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 30c822a44c228df0c2207bc375bbad7899e1428d996791c1ad796cf8d867763a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 30c822a44c228df0c2207bc375bbad7899e1428d996791c1ad796cf8d867763a
SHA3-384 hash: db4db7024415a9babfb0ed9d55b68b7770f3fff846c367b9fc43e0b530b71bd0a03abf66f180ffb2a01a7d1ce2431afb
SHA1 hash: 1ac3125e50b62f5389e4c010a3715cd5165a6db2
MD5 hash: 0bb7874bfbc2ac43e2b341f232b6206d
humanhash: july-failed-bluebird-princess
File name:p
Download: download sample
File size:831 bytes
First seen:2026-06-22 18:24:31 UTC
Last seen:2026-06-23 17:40:05 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaMzEgJRFZOUhBAF7:e9Qp+MsMzEqFcUhK7
TLSH T18201C2CA8150A900411DE65E72EB6290B920C3CF09CA4B78BF9C5D2CF78C904B026F88
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/DJCn/an/aelf ua-wget
http://129.121.114.124/KAon/an/aelf ua-wget
http://129.121.114.124/Xjun/an/aelf ua-wget
http://129.121.114.124/ml97n/an/aelf ua-wget
http://129.121.114.124/7sen/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
6
# of downloads :
98
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-22T15:34:00Z UTC
Last seen:
2026-06-22T16:06:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=aee525b8-1900-0000-7ff6-4a4834140000 pid=5172 /usr/bin/sudo guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173 /tmp/sample.bin write-file guuid=aee525b8-1900-0000-7ff6-4a4834140000 pid=5172->guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173 execve guuid=dd042bbb-1900-0000-7ff6-4a4836140000 pid=5174 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=dd042bbb-1900-0000-7ff6-4a4836140000 pid=5174 execve guuid=e389aebb-1900-0000-7ff6-4a4837140000 pid=5175 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=e389aebb-1900-0000-7ff6-4a4837140000 pid=5175 execve guuid=1b751bbc-1900-0000-7ff6-4a4838140000 pid=5176 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=1b751bbc-1900-0000-7ff6-4a4838140000 pid=5176 execve guuid=b84783bc-1900-0000-7ff6-4a4839140000 pid=5177 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=b84783bc-1900-0000-7ff6-4a4839140000 pid=5177 execve guuid=483606bd-1900-0000-7ff6-4a483a140000 pid=5178 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=483606bd-1900-0000-7ff6-4a483a140000 pid=5178 execve guuid=0cba68bd-1900-0000-7ff6-4a483b140000 pid=5179 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0cba68bd-1900-0000-7ff6-4a483b140000 pid=5179 execve guuid=3363cebd-1900-0000-7ff6-4a483c140000 pid=5180 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=3363cebd-1900-0000-7ff6-4a483c140000 pid=5180 execve guuid=b5c537be-1900-0000-7ff6-4a483d140000 pid=5181 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=b5c537be-1900-0000-7ff6-4a483d140000 pid=5181 execve guuid=4eef9abe-1900-0000-7ff6-4a483e140000 pid=5182 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=4eef9abe-1900-0000-7ff6-4a483e140000 pid=5182 execve guuid=74fea5bf-1900-0000-7ff6-4a483f140000 pid=5183 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=74fea5bf-1900-0000-7ff6-4a483f140000 pid=5183 execve guuid=61ea08c0-1900-0000-7ff6-4a4840140000 pid=5184 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=61ea08c0-1900-0000-7ff6-4a4840140000 pid=5184 execve guuid=2b146ec0-1900-0000-7ff6-4a4841140000 pid=5185 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2b146ec0-1900-0000-7ff6-4a4841140000 pid=5185 execve guuid=3f16d8c0-1900-0000-7ff6-4a4842140000 pid=5186 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=3f16d8c0-1900-0000-7ff6-4a4842140000 pid=5186 execve guuid=6cec42c1-1900-0000-7ff6-4a4843140000 pid=5187 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=6cec42c1-1900-0000-7ff6-4a4843140000 pid=5187 execve guuid=3531b8c1-1900-0000-7ff6-4a4844140000 pid=5188 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=3531b8c1-1900-0000-7ff6-4a4844140000 pid=5188 execve guuid=96d329c2-1900-0000-7ff6-4a4845140000 pid=5189 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=96d329c2-1900-0000-7ff6-4a4845140000 pid=5189 execve guuid=2fa2a2c2-1900-0000-7ff6-4a4846140000 pid=5190 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2fa2a2c2-1900-0000-7ff6-4a4846140000 pid=5190 execve guuid=f1e311c3-1900-0000-7ff6-4a4847140000 pid=5191 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=f1e311c3-1900-0000-7ff6-4a4847140000 pid=5191 execve guuid=6afe82c3-1900-0000-7ff6-4a4848140000 pid=5192 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=6afe82c3-1900-0000-7ff6-4a4848140000 pid=5192 execve guuid=880beec3-1900-0000-7ff6-4a4849140000 pid=5193 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=880beec3-1900-0000-7ff6-4a4849140000 pid=5193 execve guuid=0d725cc4-1900-0000-7ff6-4a484a140000 pid=5194 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0d725cc4-1900-0000-7ff6-4a484a140000 pid=5194 execve guuid=f80fc8c4-1900-0000-7ff6-4a484b140000 pid=5195 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=f80fc8c4-1900-0000-7ff6-4a484b140000 pid=5195 execve guuid=9fb136c5-1900-0000-7ff6-4a484c140000 pid=5196 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=9fb136c5-1900-0000-7ff6-4a484c140000 pid=5196 execve guuid=2c86a0c5-1900-0000-7ff6-4a484d140000 pid=5197 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2c86a0c5-1900-0000-7ff6-4a484d140000 pid=5197 execve guuid=9d7c07c6-1900-0000-7ff6-4a484e140000 pid=5198 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=9d7c07c6-1900-0000-7ff6-4a484e140000 pid=5198 execve guuid=ba9067c6-1900-0000-7ff6-4a484f140000 pid=5199 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ba9067c6-1900-0000-7ff6-4a484f140000 pid=5199 execve guuid=3381cdc6-1900-0000-7ff6-4a4850140000 pid=5200 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=3381cdc6-1900-0000-7ff6-4a4850140000 pid=5200 execve guuid=184a4ac7-1900-0000-7ff6-4a4851140000 pid=5201 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=184a4ac7-1900-0000-7ff6-4a4851140000 pid=5201 execve guuid=c817e5c7-1900-0000-7ff6-4a4852140000 pid=5202 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=c817e5c7-1900-0000-7ff6-4a4852140000 pid=5202 execve guuid=7f66cbc8-1900-0000-7ff6-4a4853140000 pid=5203 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=7f66cbc8-1900-0000-7ff6-4a4853140000 pid=5203 execve guuid=0b2faac9-1900-0000-7ff6-4a4854140000 pid=5204 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0b2faac9-1900-0000-7ff6-4a4854140000 pid=5204 execve guuid=9f08b1ca-1900-0000-7ff6-4a4855140000 pid=5205 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=9f08b1ca-1900-0000-7ff6-4a4855140000 pid=5205 execve guuid=4ef97fcb-1900-0000-7ff6-4a4856140000 pid=5206 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=4ef97fcb-1900-0000-7ff6-4a4856140000 pid=5206 execve guuid=11860acc-1900-0000-7ff6-4a4857140000 pid=5207 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=11860acc-1900-0000-7ff6-4a4857140000 pid=5207 execve guuid=d79a9dcc-1900-0000-7ff6-4a4858140000 pid=5208 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d79a9dcc-1900-0000-7ff6-4a4858140000 pid=5208 execve guuid=fd0833cd-1900-0000-7ff6-4a4859140000 pid=5209 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=fd0833cd-1900-0000-7ff6-4a4859140000 pid=5209 execve guuid=ba40cfcd-1900-0000-7ff6-4a485a140000 pid=5210 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ba40cfcd-1900-0000-7ff6-4a485a140000 pid=5210 execve guuid=ec0a7bce-1900-0000-7ff6-4a485b140000 pid=5211 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ec0a7bce-1900-0000-7ff6-4a485b140000 pid=5211 execve guuid=f10c1ecf-1900-0000-7ff6-4a485c140000 pid=5212 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=f10c1ecf-1900-0000-7ff6-4a485c140000 pid=5212 execve guuid=597d9ccf-1900-0000-7ff6-4a485d140000 pid=5213 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=597d9ccf-1900-0000-7ff6-4a485d140000 pid=5213 execve guuid=7b600bd0-1900-0000-7ff6-4a485e140000 pid=5214 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=7b600bd0-1900-0000-7ff6-4a485e140000 pid=5214 execve guuid=1c247ad0-1900-0000-7ff6-4a485f140000 pid=5215 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=1c247ad0-1900-0000-7ff6-4a485f140000 pid=5215 execve guuid=a50ab2d1-1900-0000-7ff6-4a4860140000 pid=5216 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=a50ab2d1-1900-0000-7ff6-4a4860140000 pid=5216 execve guuid=43d75ad2-1900-0000-7ff6-4a4861140000 pid=5217 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=43d75ad2-1900-0000-7ff6-4a4861140000 pid=5217 execve guuid=ce9befd2-1900-0000-7ff6-4a4863140000 pid=5219 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ce9befd2-1900-0000-7ff6-4a4863140000 pid=5219 execve guuid=276495d3-1900-0000-7ff6-4a4864140000 pid=5220 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=276495d3-1900-0000-7ff6-4a4864140000 pid=5220 execve guuid=ec591fd4-1900-0000-7ff6-4a4865140000 pid=5221 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ec591fd4-1900-0000-7ff6-4a4865140000 pid=5221 execve guuid=33c494d4-1900-0000-7ff6-4a4866140000 pid=5222 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=33c494d4-1900-0000-7ff6-4a4866140000 pid=5222 execve guuid=515df6d4-1900-0000-7ff6-4a4867140000 pid=5223 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=515df6d4-1900-0000-7ff6-4a4867140000 pid=5223 execve guuid=529956d5-1900-0000-7ff6-4a4868140000 pid=5224 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=529956d5-1900-0000-7ff6-4a4868140000 pid=5224 execve guuid=0c2eb9d5-1900-0000-7ff6-4a4869140000 pid=5225 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0c2eb9d5-1900-0000-7ff6-4a4869140000 pid=5225 execve guuid=d7ed58d6-1900-0000-7ff6-4a486a140000 pid=5226 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d7ed58d6-1900-0000-7ff6-4a486a140000 pid=5226 execve guuid=8e38f7d6-1900-0000-7ff6-4a486b140000 pid=5227 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8e38f7d6-1900-0000-7ff6-4a486b140000 pid=5227 execve guuid=570892d7-1900-0000-7ff6-4a486c140000 pid=5228 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=570892d7-1900-0000-7ff6-4a486c140000 pid=5228 execve guuid=edfe27d8-1900-0000-7ff6-4a486d140000 pid=5229 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=edfe27d8-1900-0000-7ff6-4a486d140000 pid=5229 execve guuid=4ea98dd8-1900-0000-7ff6-4a486e140000 pid=5230 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=4ea98dd8-1900-0000-7ff6-4a486e140000 pid=5230 execve guuid=8333f5d8-1900-0000-7ff6-4a486f140000 pid=5231 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8333f5d8-1900-0000-7ff6-4a486f140000 pid=5231 execve guuid=9a455cd9-1900-0000-7ff6-4a4870140000 pid=5232 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=9a455cd9-1900-0000-7ff6-4a4870140000 pid=5232 execve guuid=e8debdd9-1900-0000-7ff6-4a4871140000 pid=5233 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=e8debdd9-1900-0000-7ff6-4a4871140000 pid=5233 execve guuid=ee1b24da-1900-0000-7ff6-4a4872140000 pid=5234 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ee1b24da-1900-0000-7ff6-4a4872140000 pid=5234 execve guuid=c372dcda-1900-0000-7ff6-4a4875140000 pid=5237 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=c372dcda-1900-0000-7ff6-4a4875140000 pid=5237 execve guuid=b470a2db-1900-0000-7ff6-4a4877140000 pid=5239 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=b470a2db-1900-0000-7ff6-4a4877140000 pid=5239 execve guuid=d42c7cdc-1900-0000-7ff6-4a487a140000 pid=5242 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d42c7cdc-1900-0000-7ff6-4a487a140000 pid=5242 execve guuid=625f00dd-1900-0000-7ff6-4a487b140000 pid=5243 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=625f00dd-1900-0000-7ff6-4a487b140000 pid=5243 execve guuid=05edb4dd-1900-0000-7ff6-4a487c140000 pid=5244 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=05edb4dd-1900-0000-7ff6-4a487c140000 pid=5244 execve guuid=ea1a13de-1900-0000-7ff6-4a487d140000 pid=5245 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ea1a13de-1900-0000-7ff6-4a487d140000 pid=5245 execve guuid=20a775de-1900-0000-7ff6-4a487e140000 pid=5246 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=20a775de-1900-0000-7ff6-4a487e140000 pid=5246 execve guuid=e20566df-1900-0000-7ff6-4a487f140000 pid=5247 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=e20566df-1900-0000-7ff6-4a487f140000 pid=5247 execve guuid=533ee1df-1900-0000-7ff6-4a4880140000 pid=5248 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=533ee1df-1900-0000-7ff6-4a4880140000 pid=5248 execve guuid=a09367e0-1900-0000-7ff6-4a4881140000 pid=5249 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=a09367e0-1900-0000-7ff6-4a4881140000 pid=5249 execve guuid=16aeefe0-1900-0000-7ff6-4a4882140000 pid=5250 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=16aeefe0-1900-0000-7ff6-4a4882140000 pid=5250 execve guuid=3d237de1-1900-0000-7ff6-4a4883140000 pid=5251 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=3d237de1-1900-0000-7ff6-4a4883140000 pid=5251 execve guuid=20052fe2-1900-0000-7ff6-4a4884140000 pid=5252 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=20052fe2-1900-0000-7ff6-4a4884140000 pid=5252 execve guuid=0a9eb9e2-1900-0000-7ff6-4a4885140000 pid=5253 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0a9eb9e2-1900-0000-7ff6-4a4885140000 pid=5253 execve guuid=613b60e3-1900-0000-7ff6-4a4886140000 pid=5254 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=613b60e3-1900-0000-7ff6-4a4886140000 pid=5254 execve guuid=757e0fe4-1900-0000-7ff6-4a4887140000 pid=5255 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=757e0fe4-1900-0000-7ff6-4a4887140000 pid=5255 execve guuid=8f51bfe4-1900-0000-7ff6-4a4888140000 pid=5256 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8f51bfe4-1900-0000-7ff6-4a4888140000 pid=5256 execve guuid=d8548ee5-1900-0000-7ff6-4a4889140000 pid=5257 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d8548ee5-1900-0000-7ff6-4a4889140000 pid=5257 execve guuid=5d9d55e6-1900-0000-7ff6-4a488a140000 pid=5258 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=5d9d55e6-1900-0000-7ff6-4a488a140000 pid=5258 execve guuid=739b03e7-1900-0000-7ff6-4a488b140000 pid=5259 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=739b03e7-1900-0000-7ff6-4a488b140000 pid=5259 execve guuid=22c6ede7-1900-0000-7ff6-4a488c140000 pid=5260 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=22c6ede7-1900-0000-7ff6-4a488c140000 pid=5260 execve guuid=68f6c0e8-1900-0000-7ff6-4a488d140000 pid=5261 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=68f6c0e8-1900-0000-7ff6-4a488d140000 pid=5261 execve guuid=45b59be9-1900-0000-7ff6-4a488e140000 pid=5262 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=45b59be9-1900-0000-7ff6-4a488e140000 pid=5262 execve guuid=5ac152ea-1900-0000-7ff6-4a488f140000 pid=5263 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=5ac152ea-1900-0000-7ff6-4a488f140000 pid=5263 execve guuid=f71f25eb-1900-0000-7ff6-4a4890140000 pid=5264 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=f71f25eb-1900-0000-7ff6-4a4890140000 pid=5264 execve guuid=8871f5eb-1900-0000-7ff6-4a4891140000 pid=5265 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8871f5eb-1900-0000-7ff6-4a4891140000 pid=5265 execve guuid=6215c4ec-1900-0000-7ff6-4a4892140000 pid=5266 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=6215c4ec-1900-0000-7ff6-4a4892140000 pid=5266 execve guuid=2a0aa6ed-1900-0000-7ff6-4a4893140000 pid=5267 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2a0aa6ed-1900-0000-7ff6-4a4893140000 pid=5267 execve guuid=de558aee-1900-0000-7ff6-4a4894140000 pid=5268 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=de558aee-1900-0000-7ff6-4a4894140000 pid=5268 execve guuid=7f49e4ee-1900-0000-7ff6-4a4895140000 pid=5269 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=7f49e4ee-1900-0000-7ff6-4a4895140000 pid=5269 execve guuid=551ea1ef-1900-0000-7ff6-4a4896140000 pid=5270 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=551ea1ef-1900-0000-7ff6-4a4896140000 pid=5270 execve guuid=26b718f0-1900-0000-7ff6-4a4897140000 pid=5271 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=26b718f0-1900-0000-7ff6-4a4897140000 pid=5271 execve guuid=5f59d3f0-1900-0000-7ff6-4a4898140000 pid=5272 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=5f59d3f0-1900-0000-7ff6-4a4898140000 pid=5272 execve guuid=a4a66bf1-1900-0000-7ff6-4a4899140000 pid=5273 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=a4a66bf1-1900-0000-7ff6-4a4899140000 pid=5273 execve guuid=cc2f2ff2-1900-0000-7ff6-4a489a140000 pid=5274 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=cc2f2ff2-1900-0000-7ff6-4a489a140000 pid=5274 execve guuid=0ff1c3f2-1900-0000-7ff6-4a489b140000 pid=5275 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0ff1c3f2-1900-0000-7ff6-4a489b140000 pid=5275 execve guuid=37bb98f3-1900-0000-7ff6-4a489c140000 pid=5276 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=37bb98f3-1900-0000-7ff6-4a489c140000 pid=5276 execve guuid=33ea66f4-1900-0000-7ff6-4a489d140000 pid=5277 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=33ea66f4-1900-0000-7ff6-4a489d140000 pid=5277 execve guuid=ae402df5-1900-0000-7ff6-4a489e140000 pid=5278 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ae402df5-1900-0000-7ff6-4a489e140000 pid=5278 execve guuid=8522f2f5-1900-0000-7ff6-4a489f140000 pid=5279 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8522f2f5-1900-0000-7ff6-4a489f140000 pid=5279 execve guuid=8c668af6-1900-0000-7ff6-4a48a0140000 pid=5280 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8c668af6-1900-0000-7ff6-4a48a0140000 pid=5280 execve guuid=2b724df7-1900-0000-7ff6-4a48a1140000 pid=5281 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2b724df7-1900-0000-7ff6-4a48a1140000 pid=5281 execve guuid=961605f8-1900-0000-7ff6-4a48a2140000 pid=5282 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=961605f8-1900-0000-7ff6-4a48a2140000 pid=5282 execve guuid=c1f1cdf8-1900-0000-7ff6-4a48a3140000 pid=5283 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=c1f1cdf8-1900-0000-7ff6-4a48a3140000 pid=5283 execve guuid=36bc8df9-1900-0000-7ff6-4a48a4140000 pid=5284 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=36bc8df9-1900-0000-7ff6-4a48a4140000 pid=5284 execve guuid=d6e848fa-1900-0000-7ff6-4a48a5140000 pid=5285 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d6e848fa-1900-0000-7ff6-4a48a5140000 pid=5285 execve guuid=b2ccfdfa-1900-0000-7ff6-4a48a6140000 pid=5286 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=b2ccfdfa-1900-0000-7ff6-4a48a6140000 pid=5286 execve guuid=48dcc2fb-1900-0000-7ff6-4a48a7140000 pid=5287 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=48dcc2fb-1900-0000-7ff6-4a48a7140000 pid=5287 execve guuid=a8a082fc-1900-0000-7ff6-4a48a8140000 pid=5288 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=a8a082fc-1900-0000-7ff6-4a48a8140000 pid=5288 execve guuid=12e72afd-1900-0000-7ff6-4a48a9140000 pid=5289 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=12e72afd-1900-0000-7ff6-4a48a9140000 pid=5289 execve guuid=357dfbfd-1900-0000-7ff6-4a48aa140000 pid=5290 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=357dfbfd-1900-0000-7ff6-4a48aa140000 pid=5290 execve guuid=4a33bdfe-1900-0000-7ff6-4a48ab140000 pid=5291 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=4a33bdfe-1900-0000-7ff6-4a48ab140000 pid=5291 execve guuid=77b890ff-1900-0000-7ff6-4a48ac140000 pid=5292 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=77b890ff-1900-0000-7ff6-4a48ac140000 pid=5292 execve guuid=0ebd5800-1a00-0000-7ff6-4a48ad140000 pid=5293 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0ebd5800-1a00-0000-7ff6-4a48ad140000 pid=5293 execve guuid=734e2801-1a00-0000-7ff6-4a48ae140000 pid=5294 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=734e2801-1a00-0000-7ff6-4a48ae140000 pid=5294 execve guuid=0a48dd01-1a00-0000-7ff6-4a48af140000 pid=5295 /usr/bin/ls guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0a48dd01-1a00-0000-7ff6-4a48af140000 pid=5295 execve guuid=79267c02-1a00-0000-7ff6-4a48b0140000 pid=5296 /usr/bin/rm guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=79267c02-1a00-0000-7ff6-4a48b0140000 pid=5296 execve guuid=7c67fa02-1a00-0000-7ff6-4a48b1140000 pid=5297 /usr/bin/wget net send-data write-file guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=7c67fa02-1a00-0000-7ff6-4a48b1140000 pid=5297 execve guuid=2cae4a1e-1a00-0000-7ff6-4a48b9140000 pid=5305 /usr/bin/chmod guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2cae4a1e-1a00-0000-7ff6-4a48b9140000 pid=5305 execve guuid=76b18b1e-1a00-0000-7ff6-4a48ba140000 pid=5306 /usr/bin/dash guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=76b18b1e-1a00-0000-7ff6-4a48ba140000 pid=5306 clone guuid=2a96121f-1a00-0000-7ff6-4a48bc140000 pid=5308 /usr/bin/rm guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=2a96121f-1a00-0000-7ff6-4a48bc140000 pid=5308 execve guuid=b53a4c1f-1a00-0000-7ff6-4a48bd140000 pid=5309 /usr/bin/wget net send-data write-file guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=b53a4c1f-1a00-0000-7ff6-4a48bd140000 pid=5309 execve guuid=0f18d537-1a00-0000-7ff6-4a48c1140000 pid=5313 /usr/bin/chmod guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0f18d537-1a00-0000-7ff6-4a48c1140000 pid=5313 execve guuid=5f0f4938-1a00-0000-7ff6-4a48c2140000 pid=5314 /usr/bin/dash guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=5f0f4938-1a00-0000-7ff6-4a48c2140000 pid=5314 clone guuid=0730e738-1a00-0000-7ff6-4a48c5140000 pid=5317 /usr/bin/rm guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0730e738-1a00-0000-7ff6-4a48c5140000 pid=5317 execve guuid=8bec2439-1a00-0000-7ff6-4a48c7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=8bec2439-1a00-0000-7ff6-4a48c7140000 pid=5319 execve guuid=5b87b757-1a00-0000-7ff6-4a48d6140000 pid=5334 /usr/bin/chmod guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=5b87b757-1a00-0000-7ff6-4a48d6140000 pid=5334 execve guuid=967e4158-1a00-0000-7ff6-4a48d7140000 pid=5335 /usr/bin/dash guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=967e4158-1a00-0000-7ff6-4a48d7140000 pid=5335 clone guuid=26995559-1a00-0000-7ff6-4a48d9140000 pid=5337 /usr/bin/rm guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=26995559-1a00-0000-7ff6-4a48d9140000 pid=5337 execve guuid=bc3fd159-1a00-0000-7ff6-4a48da140000 pid=5338 /usr/bin/wget net send-data write-file guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=bc3fd159-1a00-0000-7ff6-4a48da140000 pid=5338 execve guuid=0c6c1479-1a00-0000-7ff6-4a48db140000 pid=5339 /usr/bin/chmod guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=0c6c1479-1a00-0000-7ff6-4a48db140000 pid=5339 execve guuid=e1477979-1a00-0000-7ff6-4a48dc140000 pid=5340 /usr/bin/dash guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=e1477979-1a00-0000-7ff6-4a48dc140000 pid=5340 clone guuid=e96f4c7a-1a00-0000-7ff6-4a48de140000 pid=5342 /usr/bin/rm guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=e96f4c7a-1a00-0000-7ff6-4a48de140000 pid=5342 execve guuid=ea0bac7a-1a00-0000-7ff6-4a48df140000 pid=5343 /usr/bin/wget net send-data write-file guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=ea0bac7a-1a00-0000-7ff6-4a48df140000 pid=5343 execve guuid=be97e698-1a00-0000-7ff6-4a48e0140000 pid=5344 /usr/bin/chmod guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=be97e698-1a00-0000-7ff6-4a48e0140000 pid=5344 execve guuid=d90c6f99-1a00-0000-7ff6-4a48e1140000 pid=5345 /usr/bin/dash guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d90c6f99-1a00-0000-7ff6-4a48e1140000 pid=5345 clone guuid=d276a79a-1a00-0000-7ff6-4a48e3140000 pid=5347 /usr/bin/rm delete-file guuid=d8ffcfba-1900-0000-7ff6-4a4835140000 pid=5173->guuid=d276a79a-1a00-0000-7ff6-4a48e3140000 pid=5347 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=7c67fa02-1a00-0000-7ff6-4a48b1140000 pid=5297->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=b53a4c1f-1a00-0000-7ff6-4a48bd140000 pid=5309->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=8bec2439-1a00-0000-7ff6-4a48c7140000 pid=5319->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=bc3fd159-1a00-0000-7ff6-4a48da140000 pid=5338->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=ea0bac7a-1a00-0000-7ff6-4a48df140000 pid=5343->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-22 18:27:22 UTC
File Type:
Text (Shell)
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 30c822a44c228df0c2207bc375bbad7899e1428d996791c1ad796cf8d867763a

(this sample)

  
Delivery method
Distributed via web download

Comments