MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3af6915cf2ed50ffb9fcf102eadfc0acd61b25467d63d90af8ff25ae0b4c1cea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3af6915cf2ed50ffb9fcf102eadfc0acd61b25467d63d90af8ff25ae0b4c1cea
SHA3-384 hash: 1835ad41925414cfc4ee336101f045ee9ea93a4c795ae3e47d39a28359be2cc4460d2631b78a2f485568a12a927ec9ea
SHA1 hash: 4db841465df247bedaceeeacf6a1e5d862dd177b
MD5 hash: 8809cf19b13b807a6b3e43ccd2bbbf88
humanhash: pluto-violet-india-eleven
File name:p
Download: download sample
File size:838 bytes
First seen:2026-06-11 02:22:37 UTC
Last seen:2026-06-11 21:19:18 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohae8g39oHW8WPueQ97:e9Qp+Msb+9oHW87eG7
TLSH T11201AFCEC102DB6041A5E49E73DB25847520C3CB16494FB8BE8C443DDBF9709B16AF48
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/FDVn/an/aelf ua-wget
http://188.132.232.81/onsNn/an/aelf ua-wget
http://188.132.232.81/6BlPn/an/aelf ua-wget
http://188.132.232.81/ygN7n/an/aelf ua-wget
http://188.132.232.81/LdPGn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-10T23:31:00Z UTC
Last seen:
2026-06-10T23:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=907b2afe-1700-0000-2f2b-840d940b0000 pid=2964 /usr/bin/sudo guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969 /tmp/sample.bin write-file guuid=907b2afe-1700-0000-2f2b-840d940b0000 pid=2964->guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969 execve guuid=c7a73601-1800-0000-2f2b-840d9a0b0000 pid=2970 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=c7a73601-1800-0000-2f2b-840d9a0b0000 pid=2970 execve guuid=e0f5a801-1800-0000-2f2b-840d9c0b0000 pid=2972 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=e0f5a801-1800-0000-2f2b-840d9c0b0000 pid=2972 execve guuid=148b2302-1800-0000-2f2b-840d9e0b0000 pid=2974 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=148b2302-1800-0000-2f2b-840d9e0b0000 pid=2974 execve guuid=c0bf9702-1800-0000-2f2b-840da00b0000 pid=2976 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=c0bf9702-1800-0000-2f2b-840da00b0000 pid=2976 execve guuid=91bf0903-1800-0000-2f2b-840da30b0000 pid=2979 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=91bf0903-1800-0000-2f2b-840da30b0000 pid=2979 execve guuid=13cd9303-1800-0000-2f2b-840da60b0000 pid=2982 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=13cd9303-1800-0000-2f2b-840da60b0000 pid=2982 execve guuid=73373904-1800-0000-2f2b-840da80b0000 pid=2984 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=73373904-1800-0000-2f2b-840da80b0000 pid=2984 execve guuid=15c15b05-1800-0000-2f2b-840dab0b0000 pid=2987 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=15c15b05-1800-0000-2f2b-840dab0b0000 pid=2987 execve guuid=8092c205-1800-0000-2f2b-840dae0b0000 pid=2990 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=8092c205-1800-0000-2f2b-840dae0b0000 pid=2990 execve guuid=abf51f06-1800-0000-2f2b-840db00b0000 pid=2992 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=abf51f06-1800-0000-2f2b-840db00b0000 pid=2992 execve guuid=af428206-1800-0000-2f2b-840db20b0000 pid=2994 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=af428206-1800-0000-2f2b-840db20b0000 pid=2994 execve guuid=3cb50007-1800-0000-2f2b-840db40b0000 pid=2996 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=3cb50007-1800-0000-2f2b-840db40b0000 pid=2996 execve guuid=02385e07-1800-0000-2f2b-840db60b0000 pid=2998 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=02385e07-1800-0000-2f2b-840db60b0000 pid=2998 execve guuid=c308d507-1800-0000-2f2b-840db70b0000 pid=2999 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=c308d507-1800-0000-2f2b-840db70b0000 pid=2999 execve guuid=21324608-1800-0000-2f2b-840db80b0000 pid=3000 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=21324608-1800-0000-2f2b-840db80b0000 pid=3000 execve guuid=27cfae08-1800-0000-2f2b-840dba0b0000 pid=3002 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=27cfae08-1800-0000-2f2b-840dba0b0000 pid=3002 execve guuid=bc1d0c09-1800-0000-2f2b-840dbc0b0000 pid=3004 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=bc1d0c09-1800-0000-2f2b-840dbc0b0000 pid=3004 execve guuid=41846709-1800-0000-2f2b-840dbe0b0000 pid=3006 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=41846709-1800-0000-2f2b-840dbe0b0000 pid=3006 execve guuid=4d16dd09-1800-0000-2f2b-840dc10b0000 pid=3009 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=4d16dd09-1800-0000-2f2b-840dc10b0000 pid=3009 execve guuid=107e680a-1800-0000-2f2b-840dc40b0000 pid=3012 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=107e680a-1800-0000-2f2b-840dc40b0000 pid=3012 execve guuid=789e020b-1800-0000-2f2b-840dc70b0000 pid=3015 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=789e020b-1800-0000-2f2b-840dc70b0000 pid=3015 execve guuid=cfd1a30b-1800-0000-2f2b-840dca0b0000 pid=3018 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=cfd1a30b-1800-0000-2f2b-840dca0b0000 pid=3018 execve guuid=7fe3860c-1800-0000-2f2b-840dcb0b0000 pid=3019 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=7fe3860c-1800-0000-2f2b-840dcb0b0000 pid=3019 execve guuid=b86c300d-1800-0000-2f2b-840dcd0b0000 pid=3021 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b86c300d-1800-0000-2f2b-840dcd0b0000 pid=3021 execve guuid=1948c30d-1800-0000-2f2b-840dd00b0000 pid=3024 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=1948c30d-1800-0000-2f2b-840dd00b0000 pid=3024 execve guuid=5694490e-1800-0000-2f2b-840dd30b0000 pid=3027 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=5694490e-1800-0000-2f2b-840dd30b0000 pid=3027 execve guuid=0baf040f-1800-0000-2f2b-840dd60b0000 pid=3030 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0baf040f-1800-0000-2f2b-840dd60b0000 pid=3030 execve guuid=b0ed7b0f-1800-0000-2f2b-840dd90b0000 pid=3033 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b0ed7b0f-1800-0000-2f2b-840dd90b0000 pid=3033 execve guuid=0f03e30f-1800-0000-2f2b-840ddb0b0000 pid=3035 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0f03e30f-1800-0000-2f2b-840ddb0b0000 pid=3035 execve guuid=60bf4910-1800-0000-2f2b-840ddd0b0000 pid=3037 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=60bf4910-1800-0000-2f2b-840ddd0b0000 pid=3037 execve guuid=e3b5b010-1800-0000-2f2b-840dde0b0000 pid=3038 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=e3b5b010-1800-0000-2f2b-840dde0b0000 pid=3038 execve guuid=09022911-1800-0000-2f2b-840ddf0b0000 pid=3039 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=09022911-1800-0000-2f2b-840ddf0b0000 pid=3039 execve guuid=9b8e9a11-1800-0000-2f2b-840de10b0000 pid=3041 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=9b8e9a11-1800-0000-2f2b-840de10b0000 pid=3041 execve guuid=b427ff11-1800-0000-2f2b-840de30b0000 pid=3043 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b427ff11-1800-0000-2f2b-840de30b0000 pid=3043 execve guuid=a2ea6012-1800-0000-2f2b-840de60b0000 pid=3046 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=a2ea6012-1800-0000-2f2b-840de60b0000 pid=3046 execve guuid=9419bd12-1800-0000-2f2b-840de80b0000 pid=3048 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=9419bd12-1800-0000-2f2b-840de80b0000 pid=3048 execve guuid=eb5b1313-1800-0000-2f2b-840deb0b0000 pid=3051 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=eb5b1313-1800-0000-2f2b-840deb0b0000 pid=3051 execve guuid=0bbe6b13-1800-0000-2f2b-840ded0b0000 pid=3053 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0bbe6b13-1800-0000-2f2b-840ded0b0000 pid=3053 execve guuid=572ac213-1800-0000-2f2b-840def0b0000 pid=3055 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=572ac213-1800-0000-2f2b-840def0b0000 pid=3055 execve guuid=5e9a2214-1800-0000-2f2b-840df20b0000 pid=3058 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=5e9a2214-1800-0000-2f2b-840df20b0000 pid=3058 execve guuid=36508414-1800-0000-2f2b-840df40b0000 pid=3060 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=36508414-1800-0000-2f2b-840df40b0000 pid=3060 execve guuid=2c69f214-1800-0000-2f2b-840df70b0000 pid=3063 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=2c69f214-1800-0000-2f2b-840df70b0000 pid=3063 execve guuid=93045a15-1800-0000-2f2b-840df90b0000 pid=3065 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=93045a15-1800-0000-2f2b-840df90b0000 pid=3065 execve guuid=958ec215-1800-0000-2f2b-840dfc0b0000 pid=3068 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=958ec215-1800-0000-2f2b-840dfc0b0000 pid=3068 execve guuid=57731416-1800-0000-2f2b-840dfe0b0000 pid=3070 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=57731416-1800-0000-2f2b-840dfe0b0000 pid=3070 execve guuid=7d567416-1800-0000-2f2b-840d010c0000 pid=3073 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=7d567416-1800-0000-2f2b-840d010c0000 pid=3073 execve guuid=8d25d516-1800-0000-2f2b-840d030c0000 pid=3075 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=8d25d516-1800-0000-2f2b-840d030c0000 pid=3075 execve guuid=364e3c17-1800-0000-2f2b-840d050c0000 pid=3077 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=364e3c17-1800-0000-2f2b-840d050c0000 pid=3077 execve guuid=ef489717-1800-0000-2f2b-840d080c0000 pid=3080 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=ef489717-1800-0000-2f2b-840d080c0000 pid=3080 execve guuid=c38f1018-1800-0000-2f2b-840d0a0c0000 pid=3082 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=c38f1018-1800-0000-2f2b-840d0a0c0000 pid=3082 execve guuid=2d6a7218-1800-0000-2f2b-840d0d0c0000 pid=3085 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=2d6a7218-1800-0000-2f2b-840d0d0c0000 pid=3085 execve guuid=0b73ce18-1800-0000-2f2b-840d0f0c0000 pid=3087 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0b73ce18-1800-0000-2f2b-840d0f0c0000 pid=3087 execve guuid=cf1b2719-1800-0000-2f2b-840d120c0000 pid=3090 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=cf1b2719-1800-0000-2f2b-840d120c0000 pid=3090 execve guuid=3d787f19-1800-0000-2f2b-840d140c0000 pid=3092 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=3d787f19-1800-0000-2f2b-840d140c0000 pid=3092 execve guuid=a41dde19-1800-0000-2f2b-840d160c0000 pid=3094 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=a41dde19-1800-0000-2f2b-840d160c0000 pid=3094 execve guuid=b497401a-1800-0000-2f2b-840d190c0000 pid=3097 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b497401a-1800-0000-2f2b-840d190c0000 pid=3097 execve guuid=ffb0a21a-1800-0000-2f2b-840d1b0c0000 pid=3099 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=ffb0a21a-1800-0000-2f2b-840d1b0c0000 pid=3099 execve guuid=0bc9041b-1800-0000-2f2b-840d1e0c0000 pid=3102 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0bc9041b-1800-0000-2f2b-840d1e0c0000 pid=3102 execve guuid=b45f621b-1800-0000-2f2b-840d200c0000 pid=3104 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b45f621b-1800-0000-2f2b-840d200c0000 pid=3104 execve guuid=09afc61b-1800-0000-2f2b-840d230c0000 pid=3107 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=09afc61b-1800-0000-2f2b-840d230c0000 pid=3107 execve guuid=3698231c-1800-0000-2f2b-840d250c0000 pid=3109 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=3698231c-1800-0000-2f2b-840d250c0000 pid=3109 execve guuid=108d821c-1800-0000-2f2b-840d270c0000 pid=3111 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=108d821c-1800-0000-2f2b-840d270c0000 pid=3111 execve guuid=4335dd1c-1800-0000-2f2b-840d2a0c0000 pid=3114 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=4335dd1c-1800-0000-2f2b-840d2a0c0000 pid=3114 execve guuid=d485401d-1800-0000-2f2b-840d2c0c0000 pid=3116 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=d485401d-1800-0000-2f2b-840d2c0c0000 pid=3116 execve guuid=f721a01d-1800-0000-2f2b-840d2e0c0000 pid=3118 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=f721a01d-1800-0000-2f2b-840d2e0c0000 pid=3118 execve guuid=2286fd1d-1800-0000-2f2b-840d310c0000 pid=3121 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=2286fd1d-1800-0000-2f2b-840d310c0000 pid=3121 execve guuid=0ddd611e-1800-0000-2f2b-840d330c0000 pid=3123 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0ddd611e-1800-0000-2f2b-840d330c0000 pid=3123 execve guuid=b5acbf1e-1800-0000-2f2b-840d360c0000 pid=3126 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b5acbf1e-1800-0000-2f2b-840d360c0000 pid=3126 execve guuid=178e7a1f-1800-0000-2f2b-840d390c0000 pid=3129 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=178e7a1f-1800-0000-2f2b-840d390c0000 pid=3129 execve guuid=deb3d61f-1800-0000-2f2b-840d3b0c0000 pid=3131 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=deb3d61f-1800-0000-2f2b-840d3b0c0000 pid=3131 execve guuid=eeb13220-1800-0000-2f2b-840d3d0c0000 pid=3133 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=eeb13220-1800-0000-2f2b-840d3d0c0000 pid=3133 execve guuid=0f8c8d20-1800-0000-2f2b-840d410c0000 pid=3137 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0f8c8d20-1800-0000-2f2b-840d410c0000 pid=3137 execve guuid=9f8ef820-1800-0000-2f2b-840d420c0000 pid=3138 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=9f8ef820-1800-0000-2f2b-840d420c0000 pid=3138 execve guuid=3d865821-1800-0000-2f2b-840d450c0000 pid=3141 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=3d865821-1800-0000-2f2b-840d450c0000 pid=3141 execve guuid=198db721-1800-0000-2f2b-840d470c0000 pid=3143 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=198db721-1800-0000-2f2b-840d470c0000 pid=3143 execve guuid=158d1522-1800-0000-2f2b-840d490c0000 pid=3145 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=158d1522-1800-0000-2f2b-840d490c0000 pid=3145 execve guuid=40a56b22-1800-0000-2f2b-840d4b0c0000 pid=3147 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=40a56b22-1800-0000-2f2b-840d4b0c0000 pid=3147 execve guuid=924dc622-1800-0000-2f2b-840d4e0c0000 pid=3150 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=924dc622-1800-0000-2f2b-840d4e0c0000 pid=3150 execve guuid=6dde2123-1800-0000-2f2b-840d500c0000 pid=3152 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=6dde2123-1800-0000-2f2b-840d500c0000 pid=3152 execve guuid=46db7823-1800-0000-2f2b-840d530c0000 pid=3155 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=46db7823-1800-0000-2f2b-840d530c0000 pid=3155 execve guuid=5c9fdb23-1800-0000-2f2b-840d550c0000 pid=3157 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=5c9fdb23-1800-0000-2f2b-840d550c0000 pid=3157 execve guuid=31eb3c24-1800-0000-2f2b-840d570c0000 pid=3159 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=31eb3c24-1800-0000-2f2b-840d570c0000 pid=3159 execve guuid=c220a624-1800-0000-2f2b-840d590c0000 pid=3161 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=c220a624-1800-0000-2f2b-840d590c0000 pid=3161 execve guuid=b5912725-1800-0000-2f2b-840d5a0c0000 pid=3162 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b5912725-1800-0000-2f2b-840d5a0c0000 pid=3162 execve guuid=7507cd25-1800-0000-2f2b-840d5c0c0000 pid=3164 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=7507cd25-1800-0000-2f2b-840d5c0c0000 pid=3164 execve guuid=8a634226-1800-0000-2f2b-840d5e0c0000 pid=3166 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=8a634226-1800-0000-2f2b-840d5e0c0000 pid=3166 execve guuid=2d53b326-1800-0000-2f2b-840d600c0000 pid=3168 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=2d53b326-1800-0000-2f2b-840d600c0000 pid=3168 execve guuid=1f931727-1800-0000-2f2b-840d630c0000 pid=3171 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=1f931727-1800-0000-2f2b-840d630c0000 pid=3171 execve guuid=abd89927-1800-0000-2f2b-840d650c0000 pid=3173 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=abd89927-1800-0000-2f2b-840d650c0000 pid=3173 execve guuid=0e161828-1800-0000-2f2b-840d680c0000 pid=3176 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0e161828-1800-0000-2f2b-840d680c0000 pid=3176 execve guuid=34cda828-1800-0000-2f2b-840d6b0c0000 pid=3179 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=34cda828-1800-0000-2f2b-840d6b0c0000 pid=3179 execve guuid=f2f25229-1800-0000-2f2b-840d6e0c0000 pid=3182 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=f2f25229-1800-0000-2f2b-840d6e0c0000 pid=3182 execve guuid=f5ddfd29-1800-0000-2f2b-840d700c0000 pid=3184 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=f5ddfd29-1800-0000-2f2b-840d700c0000 pid=3184 execve guuid=e973b42a-1800-0000-2f2b-840d730c0000 pid=3187 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=e973b42a-1800-0000-2f2b-840d730c0000 pid=3187 execve guuid=7023292b-1800-0000-2f2b-840d750c0000 pid=3189 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=7023292b-1800-0000-2f2b-840d750c0000 pid=3189 execve guuid=53c8882b-1800-0000-2f2b-840d780c0000 pid=3192 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=53c8882b-1800-0000-2f2b-840d780c0000 pid=3192 execve guuid=64bfe32b-1800-0000-2f2b-840d7a0c0000 pid=3194 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=64bfe32b-1800-0000-2f2b-840d7a0c0000 pid=3194 execve guuid=6b86462c-1800-0000-2f2b-840d7d0c0000 pid=3197 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=6b86462c-1800-0000-2f2b-840d7d0c0000 pid=3197 execve guuid=047aac2c-1800-0000-2f2b-840d7f0c0000 pid=3199 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=047aac2c-1800-0000-2f2b-840d7f0c0000 pid=3199 execve guuid=da2c062d-1800-0000-2f2b-840d820c0000 pid=3202 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=da2c062d-1800-0000-2f2b-840d820c0000 pid=3202 execve guuid=56bd762d-1800-0000-2f2b-840d840c0000 pid=3204 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=56bd762d-1800-0000-2f2b-840d840c0000 pid=3204 execve guuid=5d79d82d-1800-0000-2f2b-840d860c0000 pid=3206 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=5d79d82d-1800-0000-2f2b-840d860c0000 pid=3206 execve guuid=5dd5402e-1800-0000-2f2b-840d870c0000 pid=3207 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=5dd5402e-1800-0000-2f2b-840d870c0000 pid=3207 execve guuid=3714a92e-1800-0000-2f2b-840d890c0000 pid=3209 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=3714a92e-1800-0000-2f2b-840d890c0000 pid=3209 execve guuid=4c74112f-1800-0000-2f2b-840d8c0c0000 pid=3212 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=4c74112f-1800-0000-2f2b-840d8c0c0000 pid=3212 execve guuid=a7b1d42f-1800-0000-2f2b-840d8f0c0000 pid=3215 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=a7b1d42f-1800-0000-2f2b-840d8f0c0000 pid=3215 execve guuid=e3d03330-1800-0000-2f2b-840d920c0000 pid=3218 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=e3d03330-1800-0000-2f2b-840d920c0000 pid=3218 execve guuid=b667ae30-1800-0000-2f2b-840d940c0000 pid=3220 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b667ae30-1800-0000-2f2b-840d940c0000 pid=3220 execve guuid=6f7e1531-1800-0000-2f2b-840d970c0000 pid=3223 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=6f7e1531-1800-0000-2f2b-840d970c0000 pid=3223 execve guuid=5e6a7f31-1800-0000-2f2b-840d990c0000 pid=3225 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=5e6a7f31-1800-0000-2f2b-840d990c0000 pid=3225 execve guuid=dc7cda31-1800-0000-2f2b-840d9b0c0000 pid=3227 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=dc7cda31-1800-0000-2f2b-840d9b0c0000 pid=3227 execve guuid=b3c23032-1800-0000-2f2b-840d9d0c0000 pid=3229 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=b3c23032-1800-0000-2f2b-840d9d0c0000 pid=3229 execve guuid=1ac09732-1800-0000-2f2b-840da00c0000 pid=3232 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=1ac09732-1800-0000-2f2b-840da00c0000 pid=3232 execve guuid=1535f232-1800-0000-2f2b-840da20c0000 pid=3234 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=1535f232-1800-0000-2f2b-840da20c0000 pid=3234 execve guuid=440c5133-1800-0000-2f2b-840da40c0000 pid=3236 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=440c5133-1800-0000-2f2b-840da40c0000 pid=3236 execve guuid=37e1ae33-1800-0000-2f2b-840da60c0000 pid=3238 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=37e1ae33-1800-0000-2f2b-840da60c0000 pid=3238 execve guuid=d9041c34-1800-0000-2f2b-840da90c0000 pid=3241 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=d9041c34-1800-0000-2f2b-840da90c0000 pid=3241 execve guuid=653d7e34-1800-0000-2f2b-840dab0c0000 pid=3243 /usr/bin/ls guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=653d7e34-1800-0000-2f2b-840dab0c0000 pid=3243 execve guuid=4d37de34-1800-0000-2f2b-840dad0c0000 pid=3245 /usr/bin/rm guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=4d37de34-1800-0000-2f2b-840dad0c0000 pid=3245 execve guuid=284c2035-1800-0000-2f2b-840db00c0000 pid=3248 /usr/bin/wget net send-data write-file guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=284c2035-1800-0000-2f2b-840db00c0000 pid=3248 execve guuid=78b32d4e-1800-0000-2f2b-840dd90c0000 pid=3289 /usr/bin/chmod guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=78b32d4e-1800-0000-2f2b-840dd90c0000 pid=3289 execve guuid=0b3dc34e-1800-0000-2f2b-840dda0c0000 pid=3290 /tmp/FDV guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0b3dc34e-1800-0000-2f2b-840dda0c0000 pid=3290 execve guuid=a0c0ff4f-1800-0000-2f2b-840ddd0c0000 pid=3293 /usr/bin/rm guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=a0c0ff4f-1800-0000-2f2b-840ddd0c0000 pid=3293 execve guuid=31478d50-1800-0000-2f2b-840ddf0c0000 pid=3295 /usr/bin/wget net send-data write-file guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=31478d50-1800-0000-2f2b-840ddf0c0000 pid=3295 execve guuid=2e97a3d0-1800-0000-2f2b-840d450d0000 pid=3397 /usr/bin/chmod guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=2e97a3d0-1800-0000-2f2b-840d450d0000 pid=3397 execve guuid=bbf21ed1-1800-0000-2f2b-840d460d0000 pid=3398 /tmp/onsN guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=bbf21ed1-1800-0000-2f2b-840d460d0000 pid=3398 execve guuid=eea56dd4-1800-0000-2f2b-840d4c0d0000 pid=3404 /usr/bin/rm guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=eea56dd4-1800-0000-2f2b-840d4c0d0000 pid=3404 execve guuid=baa4b6d4-1800-0000-2f2b-840d4e0d0000 pid=3406 /usr/bin/wget net send-data write-file guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=baa4b6d4-1800-0000-2f2b-840d4e0d0000 pid=3406 execve guuid=909bcedb-1800-0000-2f2b-840d5d0d0000 pid=3421 /usr/bin/chmod guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=909bcedb-1800-0000-2f2b-840d5d0d0000 pid=3421 execve guuid=666742dc-1800-0000-2f2b-840d5e0d0000 pid=3422 /tmp/6BlP guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=666742dc-1800-0000-2f2b-840d5e0d0000 pid=3422 execve guuid=7020e8de-1800-0000-2f2b-840d640d0000 pid=3428 /usr/bin/rm guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=7020e8de-1800-0000-2f2b-840d640d0000 pid=3428 execve guuid=421a2adf-1800-0000-2f2b-840d650d0000 pid=3429 /usr/bin/wget net send-data write-file guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=421a2adf-1800-0000-2f2b-840d650d0000 pid=3429 execve guuid=4723d1e5-1800-0000-2f2b-840d710d0000 pid=3441 /usr/bin/chmod guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=4723d1e5-1800-0000-2f2b-840d710d0000 pid=3441 execve guuid=0e752fe6-1800-0000-2f2b-840d720d0000 pid=3442 /tmp/ygN7 guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=0e752fe6-1800-0000-2f2b-840d720d0000 pid=3442 execve guuid=14c73be7-1800-0000-2f2b-840d770d0000 pid=3447 /usr/bin/rm guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=14c73be7-1800-0000-2f2b-840d770d0000 pid=3447 execve guuid=4a79bee7-1800-0000-2f2b-840d790d0000 pid=3449 /usr/bin/wget net send-data write-file guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=4a79bee7-1800-0000-2f2b-840d790d0000 pid=3449 execve guuid=06ff24ee-1800-0000-2f2b-840d860d0000 pid=3462 /usr/bin/chmod guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=06ff24ee-1800-0000-2f2b-840d860d0000 pid=3462 execve guuid=ad8cbeee-1800-0000-2f2b-840d880d0000 pid=3464 /tmp/LdPG guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=ad8cbeee-1800-0000-2f2b-840d880d0000 pid=3464 execve guuid=64aa20f2-1800-0000-2f2b-840d8b0d0000 pid=3467 /usr/bin/rm delete-file guuid=f98ffa00-1800-0000-2f2b-840d990b0000 pid=2969->guuid=64aa20f2-1800-0000-2f2b-840d8b0d0000 pid=3467 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=284c2035-1800-0000-2f2b-840db00c0000 pid=3248->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=31478d50-1800-0000-2f2b-840ddf0c0000 pid=3295->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=baa4b6d4-1800-0000-2f2b-840d4e0d0000 pid=3406->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=421a2adf-1800-0000-2f2b-840d650d0000 pid=3429->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=4a79bee7-1800-0000-2f2b-840d790d0000 pid=3449->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-11 02:23:35 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3af6915cf2ed50ffb9fcf102eadfc0acd61b25467d63d90af8ff25ae0b4c1cea

(this sample)

  
Delivery method
Distributed via web download

Comments