MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3336c0fe736b0a45f375a5fef60fb7a33db39e331ccbceb372f5162846e145fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 3336c0fe736b0a45f375a5fef60fb7a33db39e331ccbceb372f5162846e145fb
SHA3-384 hash: 53f7991ccafcba355d94ad02f4c1c12a3c01c38c67fcae778b58748aa3c0323378a5bcd555b4922ed8241019585ef5a6
SHA1 hash: 6e619f6bff6f3ae7c3bcca55124e839202df6b3e
MD5 hash: c965920458364982e849e8919006ff26
humanhash: juliet-december-michigan-nuts
File name:p
Download: download sample
File size:865 bytes
First seen:2026-05-01 03:05:30 UTC
Last seen:2026-05-01 06:54:18 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCaKvjuZI4WuBl0B8l/KielrNGhalalgSlVTYM:eUh4NBCB8poNkH/TYM
TLSH T19411AFCA45112D604043446E2BD664B8B8D9D28E83060F807EED4C3EF7DC565BC39F9C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.144.31.35/wJV1n/an/aelf ua-wget
http://89.144.31.35/LZL4n/an/aelf ua-wget
http://89.144.31.35/VEO7n/an/aelf ua-wget
http://89.144.31.35/MDHHn/an/aelf ua-wget
http://89.144.31.35/BiGn/an/aelf ua-wget
http://89.144.31.35/3Apn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
136
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-01T01:17:00Z UTC
Last seen:
2026-05-01T05:44:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c3368b4a-1a00-0000-ab82-4c7b6c0a0000 pid=2668 /usr/bin/sudo guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679 /tmp/sample.bin guuid=c3368b4a-1a00-0000-ab82-4c7b6c0a0000 pid=2668->guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679 execve guuid=6b41074e-1a00-0000-ab82-4c7b7a0a0000 pid=2682 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6b41074e-1a00-0000-ab82-4c7b7a0a0000 pid=2682 execve guuid=d7f8b24e-1a00-0000-ab82-4c7b7c0a0000 pid=2684 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=d7f8b24e-1a00-0000-ab82-4c7b7c0a0000 pid=2684 execve guuid=cda0fd4e-1a00-0000-ab82-4c7b7e0a0000 pid=2686 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=cda0fd4e-1a00-0000-ab82-4c7b7e0a0000 pid=2686 execve guuid=8bbf454f-1a00-0000-ab82-4c7b800a0000 pid=2688 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=8bbf454f-1a00-0000-ab82-4c7b800a0000 pid=2688 execve guuid=22e98f4f-1a00-0000-ab82-4c7b820a0000 pid=2690 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=22e98f4f-1a00-0000-ab82-4c7b820a0000 pid=2690 execve guuid=7e7ed34f-1a00-0000-ab82-4c7b830a0000 pid=2691 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=7e7ed34f-1a00-0000-ab82-4c7b830a0000 pid=2691 execve guuid=ff311950-1a00-0000-ab82-4c7b850a0000 pid=2693 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=ff311950-1a00-0000-ab82-4c7b850a0000 pid=2693 execve guuid=10b05d50-1a00-0000-ab82-4c7b870a0000 pid=2695 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=10b05d50-1a00-0000-ab82-4c7b870a0000 pid=2695 execve guuid=d3fd0f51-1a00-0000-ab82-4c7b8a0a0000 pid=2698 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=d3fd0f51-1a00-0000-ab82-4c7b8a0a0000 pid=2698 execve guuid=199a6151-1a00-0000-ab82-4c7b8c0a0000 pid=2700 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=199a6151-1a00-0000-ab82-4c7b8c0a0000 pid=2700 execve guuid=5647a951-1a00-0000-ab82-4c7b8e0a0000 pid=2702 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=5647a951-1a00-0000-ab82-4c7b8e0a0000 pid=2702 execve guuid=b7d7ee51-1a00-0000-ab82-4c7b8f0a0000 pid=2703 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=b7d7ee51-1a00-0000-ab82-4c7b8f0a0000 pid=2703 execve guuid=eff43752-1a00-0000-ab82-4c7b920a0000 pid=2706 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=eff43752-1a00-0000-ab82-4c7b920a0000 pid=2706 execve guuid=3c677852-1a00-0000-ab82-4c7b930a0000 pid=2707 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=3c677852-1a00-0000-ab82-4c7b930a0000 pid=2707 execve guuid=4c90ba52-1a00-0000-ab82-4c7b950a0000 pid=2709 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=4c90ba52-1a00-0000-ab82-4c7b950a0000 pid=2709 execve guuid=24f9fe52-1a00-0000-ab82-4c7b970a0000 pid=2711 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=24f9fe52-1a00-0000-ab82-4c7b970a0000 pid=2711 execve guuid=32074153-1a00-0000-ab82-4c7b990a0000 pid=2713 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=32074153-1a00-0000-ab82-4c7b990a0000 pid=2713 execve guuid=014b8553-1a00-0000-ab82-4c7b9b0a0000 pid=2715 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=014b8553-1a00-0000-ab82-4c7b9b0a0000 pid=2715 execve guuid=188ac453-1a00-0000-ab82-4c7b9d0a0000 pid=2717 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=188ac453-1a00-0000-ab82-4c7b9d0a0000 pid=2717 execve guuid=e8700154-1a00-0000-ab82-4c7b9e0a0000 pid=2718 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=e8700154-1a00-0000-ab82-4c7b9e0a0000 pid=2718 execve guuid=e7d14354-1a00-0000-ab82-4c7ba00a0000 pid=2720 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=e7d14354-1a00-0000-ab82-4c7ba00a0000 pid=2720 execve guuid=14d2a854-1a00-0000-ab82-4c7ba30a0000 pid=2723 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=14d2a854-1a00-0000-ab82-4c7ba30a0000 pid=2723 execve guuid=eb94fa54-1a00-0000-ab82-4c7ba50a0000 pid=2725 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=eb94fa54-1a00-0000-ab82-4c7ba50a0000 pid=2725 execve guuid=23d56a55-1a00-0000-ab82-4c7ba80a0000 pid=2728 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=23d56a55-1a00-0000-ab82-4c7ba80a0000 pid=2728 execve guuid=776fb155-1a00-0000-ab82-4c7ba90a0000 pid=2729 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=776fb155-1a00-0000-ab82-4c7ba90a0000 pid=2729 execve guuid=c0611856-1a00-0000-ab82-4c7bac0a0000 pid=2732 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=c0611856-1a00-0000-ab82-4c7bac0a0000 pid=2732 execve guuid=49b96156-1a00-0000-ab82-4c7bae0a0000 pid=2734 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=49b96156-1a00-0000-ab82-4c7bae0a0000 pid=2734 execve guuid=5636ca56-1a00-0000-ab82-4c7bb00a0000 pid=2736 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=5636ca56-1a00-0000-ab82-4c7bb00a0000 pid=2736 execve guuid=10b92557-1a00-0000-ab82-4c7bb20a0000 pid=2738 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=10b92557-1a00-0000-ab82-4c7bb20a0000 pid=2738 execve guuid=a3c47357-1a00-0000-ab82-4c7bb40a0000 pid=2740 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a3c47357-1a00-0000-ab82-4c7bb40a0000 pid=2740 execve guuid=7c6dcb57-1a00-0000-ab82-4c7bb60a0000 pid=2742 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=7c6dcb57-1a00-0000-ab82-4c7bb60a0000 pid=2742 execve guuid=67971d58-1a00-0000-ab82-4c7bb80a0000 pid=2744 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=67971d58-1a00-0000-ab82-4c7bb80a0000 pid=2744 execve guuid=75128a58-1a00-0000-ab82-4c7bba0a0000 pid=2746 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=75128a58-1a00-0000-ab82-4c7bba0a0000 pid=2746 execve guuid=a660f358-1a00-0000-ab82-4c7bbc0a0000 pid=2748 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a660f358-1a00-0000-ab82-4c7bbc0a0000 pid=2748 execve guuid=6d166059-1a00-0000-ab82-4c7bbe0a0000 pid=2750 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6d166059-1a00-0000-ab82-4c7bbe0a0000 pid=2750 execve guuid=924db659-1a00-0000-ab82-4c7bc00a0000 pid=2752 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=924db659-1a00-0000-ab82-4c7bc00a0000 pid=2752 execve guuid=cde4fd59-1a00-0000-ab82-4c7bc20a0000 pid=2754 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=cde4fd59-1a00-0000-ab82-4c7bc20a0000 pid=2754 execve guuid=7d9b685a-1a00-0000-ab82-4c7bc40a0000 pid=2756 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=7d9b685a-1a00-0000-ab82-4c7bc40a0000 pid=2756 execve guuid=0d54cc5a-1a00-0000-ab82-4c7bc70a0000 pid=2759 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=0d54cc5a-1a00-0000-ab82-4c7bc70a0000 pid=2759 execve guuid=0014335b-1a00-0000-ab82-4c7bc90a0000 pid=2761 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=0014335b-1a00-0000-ab82-4c7bc90a0000 pid=2761 execve guuid=a0a69b5b-1a00-0000-ab82-4c7bcb0a0000 pid=2763 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a0a69b5b-1a00-0000-ab82-4c7bcb0a0000 pid=2763 execve guuid=a848fd5b-1a00-0000-ab82-4c7bcc0a0000 pid=2764 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a848fd5b-1a00-0000-ab82-4c7bcc0a0000 pid=2764 execve guuid=782f395c-1a00-0000-ab82-4c7bcd0a0000 pid=2765 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=782f395c-1a00-0000-ab82-4c7bcd0a0000 pid=2765 execve guuid=d59e7d5c-1a00-0000-ab82-4c7bce0a0000 pid=2766 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=d59e7d5c-1a00-0000-ab82-4c7bce0a0000 pid=2766 execve guuid=edddc55c-1a00-0000-ab82-4c7bd20a0000 pid=2770 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=edddc55c-1a00-0000-ab82-4c7bd20a0000 pid=2770 execve guuid=807d025d-1a00-0000-ab82-4c7bd30a0000 pid=2771 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=807d025d-1a00-0000-ab82-4c7bd30a0000 pid=2771 execve guuid=3130e25d-1a00-0000-ab82-4c7bd40a0000 pid=2772 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=3130e25d-1a00-0000-ab82-4c7bd40a0000 pid=2772 execve guuid=e51f2d5e-1a00-0000-ab82-4c7bd50a0000 pid=2773 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=e51f2d5e-1a00-0000-ab82-4c7bd50a0000 pid=2773 execve guuid=e3966d5e-1a00-0000-ab82-4c7bd70a0000 pid=2775 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=e3966d5e-1a00-0000-ab82-4c7bd70a0000 pid=2775 execve guuid=d224a85e-1a00-0000-ab82-4c7bd90a0000 pid=2777 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=d224a85e-1a00-0000-ab82-4c7bd90a0000 pid=2777 execve guuid=fbf0e25e-1a00-0000-ab82-4c7bdb0a0000 pid=2779 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=fbf0e25e-1a00-0000-ab82-4c7bdb0a0000 pid=2779 execve guuid=1033225f-1a00-0000-ab82-4c7bdd0a0000 pid=2781 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=1033225f-1a00-0000-ab82-4c7bdd0a0000 pid=2781 execve guuid=32d5675f-1a00-0000-ab82-4c7bdf0a0000 pid=2783 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=32d5675f-1a00-0000-ab82-4c7bdf0a0000 pid=2783 execve guuid=c814ad5f-1a00-0000-ab82-4c7be00a0000 pid=2784 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=c814ad5f-1a00-0000-ab82-4c7be00a0000 pid=2784 execve guuid=7cacf55f-1a00-0000-ab82-4c7be20a0000 pid=2786 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=7cacf55f-1a00-0000-ab82-4c7be20a0000 pid=2786 execve guuid=51fb5660-1a00-0000-ab82-4c7be40a0000 pid=2788 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=51fb5660-1a00-0000-ab82-4c7be40a0000 pid=2788 execve guuid=184ac160-1a00-0000-ab82-4c7be60a0000 pid=2790 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=184ac160-1a00-0000-ab82-4c7be60a0000 pid=2790 execve guuid=1e732761-1a00-0000-ab82-4c7be80a0000 pid=2792 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=1e732761-1a00-0000-ab82-4c7be80a0000 pid=2792 execve guuid=40f19661-1a00-0000-ab82-4c7bea0a0000 pid=2794 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=40f19661-1a00-0000-ab82-4c7bea0a0000 pid=2794 execve guuid=80fa0362-1a00-0000-ab82-4c7beb0a0000 pid=2795 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=80fa0362-1a00-0000-ab82-4c7beb0a0000 pid=2795 execve guuid=b0838b62-1a00-0000-ab82-4c7bec0a0000 pid=2796 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=b0838b62-1a00-0000-ab82-4c7bec0a0000 pid=2796 execve guuid=f54b3763-1a00-0000-ab82-4c7bee0a0000 pid=2798 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=f54b3763-1a00-0000-ab82-4c7bee0a0000 pid=2798 execve guuid=6920c763-1a00-0000-ab82-4c7bef0a0000 pid=2799 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6920c763-1a00-0000-ab82-4c7bef0a0000 pid=2799 execve guuid=04783d64-1a00-0000-ab82-4c7bf00a0000 pid=2800 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=04783d64-1a00-0000-ab82-4c7bf00a0000 pid=2800 execve guuid=aa22b364-1a00-0000-ab82-4c7bf10a0000 pid=2801 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=aa22b364-1a00-0000-ab82-4c7bf10a0000 pid=2801 execve guuid=70181e65-1a00-0000-ab82-4c7bf30a0000 pid=2803 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=70181e65-1a00-0000-ab82-4c7bf30a0000 pid=2803 execve guuid=7e8f7965-1a00-0000-ab82-4c7bf50a0000 pid=2805 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=7e8f7965-1a00-0000-ab82-4c7bf50a0000 pid=2805 execve guuid=5b95db65-1a00-0000-ab82-4c7bf70a0000 pid=2807 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=5b95db65-1a00-0000-ab82-4c7bf70a0000 pid=2807 execve guuid=31603d66-1a00-0000-ab82-4c7bf90a0000 pid=2809 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=31603d66-1a00-0000-ab82-4c7bf90a0000 pid=2809 execve guuid=a44b9966-1a00-0000-ab82-4c7bfb0a0000 pid=2811 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a44b9966-1a00-0000-ab82-4c7bfb0a0000 pid=2811 execve guuid=6693f966-1a00-0000-ab82-4c7bfd0a0000 pid=2813 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6693f966-1a00-0000-ab82-4c7bfd0a0000 pid=2813 execve guuid=f8da5167-1a00-0000-ab82-4c7bfe0a0000 pid=2814 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=f8da5167-1a00-0000-ab82-4c7bfe0a0000 pid=2814 execve guuid=2c709367-1a00-0000-ab82-4c7bff0a0000 pid=2815 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=2c709367-1a00-0000-ab82-4c7bff0a0000 pid=2815 execve guuid=4573d767-1a00-0000-ab82-4c7b010b0000 pid=2817 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=4573d767-1a00-0000-ab82-4c7b010b0000 pid=2817 execve guuid=2a5a1868-1a00-0000-ab82-4c7b020b0000 pid=2818 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=2a5a1868-1a00-0000-ab82-4c7b020b0000 pid=2818 execve guuid=b7496168-1a00-0000-ab82-4c7b030b0000 pid=2819 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=b7496168-1a00-0000-ab82-4c7b030b0000 pid=2819 execve guuid=dfa3af68-1a00-0000-ab82-4c7b040b0000 pid=2820 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=dfa3af68-1a00-0000-ab82-4c7b040b0000 pid=2820 execve guuid=0dd7f768-1a00-0000-ab82-4c7b050b0000 pid=2821 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=0dd7f768-1a00-0000-ab82-4c7b050b0000 pid=2821 execve guuid=1fad3d69-1a00-0000-ab82-4c7b070b0000 pid=2823 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=1fad3d69-1a00-0000-ab82-4c7b070b0000 pid=2823 execve guuid=ef9b8069-1a00-0000-ab82-4c7b090b0000 pid=2825 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=ef9b8069-1a00-0000-ab82-4c7b090b0000 pid=2825 execve guuid=50c0c469-1a00-0000-ab82-4c7b0b0b0000 pid=2827 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=50c0c469-1a00-0000-ab82-4c7b0b0b0000 pid=2827 execve guuid=1b500e6a-1a00-0000-ab82-4c7b0c0b0000 pid=2828 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=1b500e6a-1a00-0000-ab82-4c7b0c0b0000 pid=2828 execve guuid=22b7516a-1a00-0000-ab82-4c7b0e0b0000 pid=2830 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=22b7516a-1a00-0000-ab82-4c7b0e0b0000 pid=2830 execve guuid=25fe986a-1a00-0000-ab82-4c7b100b0000 pid=2832 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=25fe986a-1a00-0000-ab82-4c7b100b0000 pid=2832 execve guuid=b832de6a-1a00-0000-ab82-4c7b110b0000 pid=2833 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=b832de6a-1a00-0000-ab82-4c7b110b0000 pid=2833 execve guuid=f47c206b-1a00-0000-ab82-4c7b130b0000 pid=2835 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=f47c206b-1a00-0000-ab82-4c7b130b0000 pid=2835 execve guuid=04d86c6b-1a00-0000-ab82-4c7b140b0000 pid=2836 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=04d86c6b-1a00-0000-ab82-4c7b140b0000 pid=2836 execve guuid=6c1bba6b-1a00-0000-ab82-4c7b160b0000 pid=2838 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6c1bba6b-1a00-0000-ab82-4c7b160b0000 pid=2838 execve guuid=a2d3fa6b-1a00-0000-ab82-4c7b170b0000 pid=2839 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a2d3fa6b-1a00-0000-ab82-4c7b170b0000 pid=2839 execve guuid=4e944c6c-1a00-0000-ab82-4c7b180b0000 pid=2840 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=4e944c6c-1a00-0000-ab82-4c7b180b0000 pid=2840 execve guuid=ac659e6c-1a00-0000-ab82-4c7b190b0000 pid=2841 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=ac659e6c-1a00-0000-ab82-4c7b190b0000 pid=2841 execve guuid=1971ed6c-1a00-0000-ab82-4c7b1a0b0000 pid=2842 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=1971ed6c-1a00-0000-ab82-4c7b1a0b0000 pid=2842 execve guuid=e4cf3d6d-1a00-0000-ab82-4c7b1b0b0000 pid=2843 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=e4cf3d6d-1a00-0000-ab82-4c7b1b0b0000 pid=2843 execve guuid=73f28d6d-1a00-0000-ab82-4c7b1c0b0000 pid=2844 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=73f28d6d-1a00-0000-ab82-4c7b1c0b0000 pid=2844 execve guuid=c3a2e46d-1a00-0000-ab82-4c7b1e0b0000 pid=2846 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=c3a2e46d-1a00-0000-ab82-4c7b1e0b0000 pid=2846 execve guuid=0a8e316e-1a00-0000-ab82-4c7b200b0000 pid=2848 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=0a8e316e-1a00-0000-ab82-4c7b200b0000 pid=2848 execve guuid=865e7b6e-1a00-0000-ab82-4c7b220b0000 pid=2850 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=865e7b6e-1a00-0000-ab82-4c7b220b0000 pid=2850 execve guuid=94b0bf6e-1a00-0000-ab82-4c7b240b0000 pid=2852 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=94b0bf6e-1a00-0000-ab82-4c7b240b0000 pid=2852 execve guuid=6576126f-1a00-0000-ab82-4c7b260b0000 pid=2854 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6576126f-1a00-0000-ab82-4c7b260b0000 pid=2854 execve guuid=6c82636f-1a00-0000-ab82-4c7b280b0000 pid=2856 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6c82636f-1a00-0000-ab82-4c7b280b0000 pid=2856 execve guuid=c8eab16f-1a00-0000-ab82-4c7b290b0000 pid=2857 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=c8eab16f-1a00-0000-ab82-4c7b290b0000 pid=2857 execve guuid=65dc2970-1a00-0000-ab82-4c7b2a0b0000 pid=2858 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=65dc2970-1a00-0000-ab82-4c7b2a0b0000 pid=2858 execve guuid=fce3a470-1a00-0000-ab82-4c7b2b0b0000 pid=2859 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=fce3a470-1a00-0000-ab82-4c7b2b0b0000 pid=2859 execve guuid=eef60a71-1a00-0000-ab82-4c7b2c0b0000 pid=2860 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=eef60a71-1a00-0000-ab82-4c7b2c0b0000 pid=2860 execve guuid=180f7071-1a00-0000-ab82-4c7b2d0b0000 pid=2861 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=180f7071-1a00-0000-ab82-4c7b2d0b0000 pid=2861 execve guuid=9059d671-1a00-0000-ab82-4c7b2e0b0000 pid=2862 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=9059d671-1a00-0000-ab82-4c7b2e0b0000 pid=2862 execve guuid=49503a72-1a00-0000-ab82-4c7b2f0b0000 pid=2863 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=49503a72-1a00-0000-ab82-4c7b2f0b0000 pid=2863 execve guuid=b80e9772-1a00-0000-ab82-4c7b300b0000 pid=2864 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=b80e9772-1a00-0000-ab82-4c7b300b0000 pid=2864 execve guuid=abe3fe72-1a00-0000-ab82-4c7b310b0000 pid=2865 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=abe3fe72-1a00-0000-ab82-4c7b310b0000 pid=2865 execve guuid=20667f73-1a00-0000-ab82-4c7b320b0000 pid=2866 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=20667f73-1a00-0000-ab82-4c7b320b0000 pid=2866 execve guuid=f9e7d273-1a00-0000-ab82-4c7b340b0000 pid=2868 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=f9e7d273-1a00-0000-ab82-4c7b340b0000 pid=2868 execve guuid=421c1b74-1a00-0000-ab82-4c7b350b0000 pid=2869 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=421c1b74-1a00-0000-ab82-4c7b350b0000 pid=2869 execve guuid=a28f6074-1a00-0000-ab82-4c7b360b0000 pid=2870 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=a28f6074-1a00-0000-ab82-4c7b360b0000 pid=2870 execve guuid=be699f74-1a00-0000-ab82-4c7b380b0000 pid=2872 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=be699f74-1a00-0000-ab82-4c7b380b0000 pid=2872 execve guuid=0691e374-1a00-0000-ab82-4c7b390b0000 pid=2873 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=0691e374-1a00-0000-ab82-4c7b390b0000 pid=2873 execve guuid=12ab2675-1a00-0000-ab82-4c7b3b0b0000 pid=2875 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=12ab2675-1a00-0000-ab82-4c7b3b0b0000 pid=2875 execve guuid=44b26c75-1a00-0000-ab82-4c7b3d0b0000 pid=2877 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=44b26c75-1a00-0000-ab82-4c7b3d0b0000 pid=2877 execve guuid=abb8bc75-1a00-0000-ab82-4c7b3f0b0000 pid=2879 /usr/bin/readlink guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=abb8bc75-1a00-0000-ab82-4c7b3f0b0000 pid=2879 execve guuid=62bcfb75-1a00-0000-ab82-4c7b400b0000 pid=2880 /usr/bin/rm guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=62bcfb75-1a00-0000-ab82-4c7b400b0000 pid=2880 execve guuid=6f645d76-1a00-0000-ab82-4c7b420b0000 pid=2882 /usr/bin/wget net send-data write-file guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=6f645d76-1a00-0000-ab82-4c7b420b0000 pid=2882 execve guuid=eecc957e-1a00-0000-ab82-4c7b450b0000 pid=2885 /usr/bin/chmod guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=eecc957e-1a00-0000-ab82-4c7b450b0000 pid=2885 execve guuid=51c2017f-1a00-0000-ab82-4c7b460b0000 pid=2886 /tmp/wJV1 guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=51c2017f-1a00-0000-ab82-4c7b460b0000 pid=2886 execve guuid=720dd67f-1a00-0000-ab82-4c7b4b0b0000 pid=2891 /usr/bin/rm guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=720dd67f-1a00-0000-ab82-4c7b4b0b0000 pid=2891 execve guuid=fa3f1680-1a00-0000-ab82-4c7b4d0b0000 pid=2893 /usr/bin/wget guuid=7c468d4d-1a00-0000-ab82-4c7b770a0000 pid=2679->guuid=fa3f1680-1a00-0000-ab82-4c7b4d0b0000 pid=2893 execve 7687bf85-6859-5258-bc6b-ab045eb7d95c 89.144.31.35:80 guuid=6f645d76-1a00-0000-ab82-4c7b420b0000 pid=2882->7687bf85-6859-5258-bc6b-ab045eb7d95c send: 131B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-01 06:56:46 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion linux
Behaviour
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3336c0fe736b0a45f375a5fef60fb7a33db39e331ccbceb372f5162846e145fb

(this sample)

  
Delivery method
Distributed via web download

Comments