MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e4748230fb13db23696117efea3b5db43b95d1d6da5c2e08078531ed61cac21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 3e4748230fb13db23696117efea3b5db43b95d1d6da5c2e08078531ed61cac21
SHA3-384 hash: 6e8e09b3d7ae316535bfbe5ae162865d298fd5226fae6f0ed78258dfeea33b1add4496a4576a7e396202feb0360aee6f
SHA1 hash: 6e094fb13d521fad3bd25efd73203df752c6eae7
MD5 hash: 4bb7e8f16a95c923a9bb1bf5fd5bebd0
humanhash: cat-yankee-friend-west
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-19 05:03:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:Uwr6Xwv6LRi6RNIGiMQRFL6RFjFSYFDsz6s3BgR6gGUHk6itUmFB96AfIRMiRllx:bkBR7IF2FjFSYFI33DmmFtkRliU
TLSH T172314FEA4414163A1203CEDE73B33958715CE2EB289BC795DC480EAE8A8C1DCB192F95
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/446a81n/an/aelf ua-wget
http://5.182.210.61/a1b2d3n/an/aelf ua-wget
http://5.182.210.61/59cfe2n/an/aelf ua-wget
http://5.182.210.61/ee8263n/an/aelf ua-wget
http://5.182.210.61/377061n/an/aelf ua-wget
http://5.182.210.61/910471n/an/aelf ua-wget
http://5.182.210.61/f991c0n/an/aelf ua-wget
http://5.182.210.61/c3449bn/an/aelf ua-wget
http://5.182.210.61/1840dbn/an/aelf ua-wget
http://5.182.210.61/038355n/an/aelf ua-wget
http://5.182.210.61/9e4ac7n/an/aelf ua-wget
http://5.182.210.61/d401f7n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=6675bc2b-1900-0000-4915-98c6c2120000 pid=4802 /usr/bin/sudo guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808 /tmp/sample.bin guuid=6675bc2b-1900-0000-4915-98c6c2120000 pid=4802->guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808 execve guuid=4a152f2e-1900-0000-4915-98c6cc120000 pid=4812 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=4a152f2e-1900-0000-4915-98c6cc120000 pid=4812 execve guuid=9ed40733-1900-0000-4915-98c6df120000 pid=4831 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=9ed40733-1900-0000-4915-98c6df120000 pid=4831 execve guuid=03db813c-1900-0000-4915-98c6ff120000 pid=4863 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=03db813c-1900-0000-4915-98c6ff120000 pid=4863 execve guuid=143ad83c-1900-0000-4915-98c602130000 pid=4866 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=143ad83c-1900-0000-4915-98c602130000 pid=4866 clone guuid=0620143d-1900-0000-4915-98c604130000 pid=4868 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=0620143d-1900-0000-4915-98c604130000 pid=4868 execve guuid=23ed663d-1900-0000-4915-98c607130000 pid=4871 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=23ed663d-1900-0000-4915-98c607130000 pid=4871 execve guuid=b73fa43d-1900-0000-4915-98c609130000 pid=4873 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=b73fa43d-1900-0000-4915-98c609130000 pid=4873 execve guuid=dced1440-1900-0000-4915-98c614130000 pid=4884 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=dced1440-1900-0000-4915-98c614130000 pid=4884 execve guuid=7d7c4143-1900-0000-4915-98c622130000 pid=4898 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=7d7c4143-1900-0000-4915-98c622130000 pid=4898 execve guuid=c80f7c43-1900-0000-4915-98c624130000 pid=4900 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=c80f7c43-1900-0000-4915-98c624130000 pid=4900 clone guuid=d138e043-1900-0000-4915-98c627130000 pid=4903 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=d138e043-1900-0000-4915-98c627130000 pid=4903 execve guuid=fe822844-1900-0000-4915-98c62a130000 pid=4906 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=fe822844-1900-0000-4915-98c62a130000 pid=4906 execve guuid=fc466a44-1900-0000-4915-98c62c130000 pid=4908 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=fc466a44-1900-0000-4915-98c62c130000 pid=4908 execve guuid=23a8cc46-1900-0000-4915-98c635130000 pid=4917 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=23a8cc46-1900-0000-4915-98c635130000 pid=4917 execve guuid=129a404a-1900-0000-4915-98c641130000 pid=4929 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=129a404a-1900-0000-4915-98c641130000 pid=4929 execve guuid=7cf8034b-1900-0000-4915-98c643130000 pid=4931 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=7cf8034b-1900-0000-4915-98c643130000 pid=4931 clone guuid=0b0b774b-1900-0000-4915-98c647130000 pid=4935 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=0b0b774b-1900-0000-4915-98c647130000 pid=4935 execve guuid=f89cec4b-1900-0000-4915-98c649130000 pid=4937 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=f89cec4b-1900-0000-4915-98c649130000 pid=4937 execve guuid=a2d3574c-1900-0000-4915-98c64c130000 pid=4940 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=a2d3574c-1900-0000-4915-98c64c130000 pid=4940 execve guuid=277d484f-1900-0000-4915-98c657130000 pid=4951 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=277d484f-1900-0000-4915-98c657130000 pid=4951 execve guuid=7f129c53-1900-0000-4915-98c661130000 pid=4961 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=7f129c53-1900-0000-4915-98c661130000 pid=4961 execve guuid=cdace853-1900-0000-4915-98c664130000 pid=4964 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=cdace853-1900-0000-4915-98c664130000 pid=4964 clone guuid=fa552754-1900-0000-4915-98c667130000 pid=4967 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=fa552754-1900-0000-4915-98c667130000 pid=4967 execve guuid=a10f7654-1900-0000-4915-98c669130000 pid=4969 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=a10f7654-1900-0000-4915-98c669130000 pid=4969 execve guuid=0495b954-1900-0000-4915-98c66a130000 pid=4970 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=0495b954-1900-0000-4915-98c66a130000 pid=4970 execve guuid=53ce2557-1900-0000-4915-98c66f130000 pid=4975 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=53ce2557-1900-0000-4915-98c66f130000 pid=4975 execve guuid=828d4d5d-1900-0000-4915-98c689130000 pid=5001 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=828d4d5d-1900-0000-4915-98c689130000 pid=5001 execve guuid=eab68b5d-1900-0000-4915-98c68b130000 pid=5003 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=eab68b5d-1900-0000-4915-98c68b130000 pid=5003 clone guuid=345abb5d-1900-0000-4915-98c690130000 pid=5008 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=345abb5d-1900-0000-4915-98c690130000 pid=5008 execve guuid=4ccffe5d-1900-0000-4915-98c692130000 pid=5010 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=4ccffe5d-1900-0000-4915-98c692130000 pid=5010 execve guuid=7c973b5e-1900-0000-4915-98c695130000 pid=5013 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=7c973b5e-1900-0000-4915-98c695130000 pid=5013 execve guuid=7393fb60-1900-0000-4915-98c6a2130000 pid=5026 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=7393fb60-1900-0000-4915-98c6a2130000 pid=5026 execve guuid=693e5064-1900-0000-4915-98c6b2130000 pid=5042 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=693e5064-1900-0000-4915-98c6b2130000 pid=5042 execve guuid=1daa9664-1900-0000-4915-98c6b6130000 pid=5046 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=1daa9664-1900-0000-4915-98c6b6130000 pid=5046 clone guuid=f5add464-1900-0000-4915-98c6b8130000 pid=5048 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=f5add464-1900-0000-4915-98c6b8130000 pid=5048 execve guuid=f3831a65-1900-0000-4915-98c6ba130000 pid=5050 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=f3831a65-1900-0000-4915-98c6ba130000 pid=5050 execve guuid=24e76165-1900-0000-4915-98c6bc130000 pid=5052 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=24e76165-1900-0000-4915-98c6bc130000 pid=5052 execve guuid=49b4e167-1900-0000-4915-98c6c8130000 pid=5064 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=49b4e167-1900-0000-4915-98c6c8130000 pid=5064 execve guuid=d2d89e6b-1900-0000-4915-98c6d5130000 pid=5077 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=d2d89e6b-1900-0000-4915-98c6d5130000 pid=5077 execve guuid=5b81ea6b-1900-0000-4915-98c6d6130000 pid=5078 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=5b81ea6b-1900-0000-4915-98c6d6130000 pid=5078 clone guuid=778e346c-1900-0000-4915-98c6d9130000 pid=5081 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=778e346c-1900-0000-4915-98c6d9130000 pid=5081 execve guuid=45ff826c-1900-0000-4915-98c6da130000 pid=5082 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=45ff826c-1900-0000-4915-98c6da130000 pid=5082 execve guuid=5100c96c-1900-0000-4915-98c6dc130000 pid=5084 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=5100c96c-1900-0000-4915-98c6dc130000 pid=5084 execve guuid=34e67c6f-1900-0000-4915-98c6e3130000 pid=5091 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=34e67c6f-1900-0000-4915-98c6e3130000 pid=5091 execve guuid=a4cf2474-1900-0000-4915-98c6f1130000 pid=5105 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=a4cf2474-1900-0000-4915-98c6f1130000 pid=5105 execve guuid=1a267874-1900-0000-4915-98c6f3130000 pid=5107 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=1a267874-1900-0000-4915-98c6f3130000 pid=5107 clone guuid=74ddab74-1900-0000-4915-98c6f5130000 pid=5109 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=74ddab74-1900-0000-4915-98c6f5130000 pid=5109 execve guuid=e82cfa74-1900-0000-4915-98c6f7130000 pid=5111 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=e82cfa74-1900-0000-4915-98c6f7130000 pid=5111 execve guuid=b64c3c75-1900-0000-4915-98c6f9130000 pid=5113 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=b64c3c75-1900-0000-4915-98c6f9130000 pid=5113 execve guuid=3cbfaa77-1900-0000-4915-98c602140000 pid=5122 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=3cbfaa77-1900-0000-4915-98c602140000 pid=5122 execve guuid=f2d12c7b-1900-0000-4915-98c60b140000 pid=5131 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=f2d12c7b-1900-0000-4915-98c60b140000 pid=5131 execve guuid=1927767b-1900-0000-4915-98c60c140000 pid=5132 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=1927767b-1900-0000-4915-98c60c140000 pid=5132 clone guuid=e550ae7b-1900-0000-4915-98c60f140000 pid=5135 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=e550ae7b-1900-0000-4915-98c60f140000 pid=5135 execve guuid=f2ad027c-1900-0000-4915-98c611140000 pid=5137 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=f2ad027c-1900-0000-4915-98c611140000 pid=5137 execve guuid=6934537c-1900-0000-4915-98c613140000 pid=5139 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=6934537c-1900-0000-4915-98c613140000 pid=5139 execve guuid=16cb837f-1900-0000-4915-98c61d140000 pid=5149 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=16cb837f-1900-0000-4915-98c61d140000 pid=5149 execve guuid=ca6c4984-1900-0000-4915-98c62a140000 pid=5162 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=ca6c4984-1900-0000-4915-98c62a140000 pid=5162 execve guuid=a74e9284-1900-0000-4915-98c62b140000 pid=5163 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=a74e9284-1900-0000-4915-98c62b140000 pid=5163 clone guuid=3a37cc84-1900-0000-4915-98c630140000 pid=5168 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=3a37cc84-1900-0000-4915-98c630140000 pid=5168 execve guuid=3b7e1185-1900-0000-4915-98c632140000 pid=5170 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=3b7e1185-1900-0000-4915-98c632140000 pid=5170 execve guuid=29445b85-1900-0000-4915-98c633140000 pid=5171 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=29445b85-1900-0000-4915-98c633140000 pid=5171 execve guuid=5bd9c487-1900-0000-4915-98c642140000 pid=5186 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=5bd9c487-1900-0000-4915-98c642140000 pid=5186 execve guuid=1f29958b-1900-0000-4915-98c65f140000 pid=5215 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=1f29958b-1900-0000-4915-98c65f140000 pid=5215 execve guuid=a715f68b-1900-0000-4915-98c662140000 pid=5218 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=a715f68b-1900-0000-4915-98c662140000 pid=5218 clone guuid=94232c8c-1900-0000-4915-98c664140000 pid=5220 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=94232c8c-1900-0000-4915-98c664140000 pid=5220 execve guuid=b033748c-1900-0000-4915-98c667140000 pid=5223 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=b033748c-1900-0000-4915-98c667140000 pid=5223 execve guuid=8bf4b88c-1900-0000-4915-98c668140000 pid=5224 /usr/bin/wget net send-data guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=8bf4b88c-1900-0000-4915-98c668140000 pid=5224 execve guuid=b4d7218f-1900-0000-4915-98c66a140000 pid=5226 /usr/bin/curl net send-data write-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=b4d7218f-1900-0000-4915-98c66a140000 pid=5226 execve guuid=d2b22793-1900-0000-4915-98c66b140000 pid=5227 /usr/bin/chmod guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=d2b22793-1900-0000-4915-98c66b140000 pid=5227 execve guuid=751a7193-1900-0000-4915-98c66c140000 pid=5228 /usr/bin/bash guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=751a7193-1900-0000-4915-98c66c140000 pid=5228 clone guuid=5230b993-1900-0000-4915-98c66e140000 pid=5230 /usr/bin/rm delete-file guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=5230b993-1900-0000-4915-98c66e140000 pid=5230 execve guuid=96e82494-1900-0000-4915-98c66f140000 pid=5231 /usr/bin/rm guuid=60e5652d-1900-0000-4915-98c6c8120000 pid=4808->guuid=96e82494-1900-0000-4915-98c66f140000 pid=5231 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=4a152f2e-1900-0000-4915-98c6cc120000 pid=4812->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=9ed40733-1900-0000-4915-98c6df120000 pid=4831->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=5511f13c-1900-0000-4915-98c603130000 pid=4867 /usr/bin/bash guuid=143ad83c-1900-0000-4915-98c602130000 pid=4866->guuid=5511f13c-1900-0000-4915-98c603130000 pid=4867 clone guuid=b73fa43d-1900-0000-4915-98c609130000 pid=4873->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=dced1440-1900-0000-4915-98c614130000 pid=4884->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0c839143-1900-0000-4915-98c625130000 pid=4901 /usr/bin/bash guuid=c80f7c43-1900-0000-4915-98c624130000 pid=4900->guuid=0c839143-1900-0000-4915-98c625130000 pid=4901 clone guuid=fc466a44-1900-0000-4915-98c62c130000 pid=4908->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=23a8cc46-1900-0000-4915-98c635130000 pid=4917->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=5d18274b-1900-0000-4915-98c645130000 pid=4933 /usr/bin/bash guuid=7cf8034b-1900-0000-4915-98c643130000 pid=4931->guuid=5d18274b-1900-0000-4915-98c645130000 pid=4933 clone guuid=a2d3574c-1900-0000-4915-98c64c130000 pid=4940->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=277d484f-1900-0000-4915-98c657130000 pid=4951->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=de890254-1900-0000-4915-98c665130000 pid=4965 /usr/bin/bash guuid=cdace853-1900-0000-4915-98c664130000 pid=4964->guuid=de890254-1900-0000-4915-98c665130000 pid=4965 clone guuid=0495b954-1900-0000-4915-98c66a130000 pid=4970->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=53ce2557-1900-0000-4915-98c66f130000 pid=4975->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=71aaa05d-1900-0000-4915-98c68f130000 pid=5007 /usr/bin/bash guuid=eab68b5d-1900-0000-4915-98c68b130000 pid=5003->guuid=71aaa05d-1900-0000-4915-98c68f130000 pid=5007 clone guuid=7c973b5e-1900-0000-4915-98c695130000 pid=5013->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=7393fb60-1900-0000-4915-98c6a2130000 pid=5026->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=9549ad64-1900-0000-4915-98c6b7130000 pid=5047 /usr/bin/bash guuid=1daa9664-1900-0000-4915-98c6b6130000 pid=5046->guuid=9549ad64-1900-0000-4915-98c6b7130000 pid=5047 clone guuid=24e76165-1900-0000-4915-98c6bc130000 pid=5052->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=49b4e167-1900-0000-4915-98c6c8130000 pid=5064->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=d0a4016c-1900-0000-4915-98c6d7130000 pid=5079 /usr/bin/bash guuid=5b81ea6b-1900-0000-4915-98c6d6130000 pid=5078->guuid=d0a4016c-1900-0000-4915-98c6d7130000 pid=5079 clone guuid=5100c96c-1900-0000-4915-98c6dc130000 pid=5084->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=34e67c6f-1900-0000-4915-98c6e3130000 pid=5091->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=9e5f9074-1900-0000-4915-98c6f4130000 pid=5108 /usr/bin/bash guuid=1a267874-1900-0000-4915-98c6f3130000 pid=5107->guuid=9e5f9074-1900-0000-4915-98c6f4130000 pid=5108 clone guuid=b64c3c75-1900-0000-4915-98c6f9130000 pid=5113->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=3cbfaa77-1900-0000-4915-98c602140000 pid=5122->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ae908c7b-1900-0000-4915-98c60e140000 pid=5134 /usr/bin/bash guuid=1927767b-1900-0000-4915-98c60c140000 pid=5132->guuid=ae908c7b-1900-0000-4915-98c60e140000 pid=5134 clone guuid=6934537c-1900-0000-4915-98c613140000 pid=5139->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=16cb837f-1900-0000-4915-98c61d140000 pid=5149->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=9e68aa84-1900-0000-4915-98c62e140000 pid=5166 /usr/bin/bash guuid=a74e9284-1900-0000-4915-98c62b140000 pid=5163->guuid=9e68aa84-1900-0000-4915-98c62e140000 pid=5166 clone guuid=29445b85-1900-0000-4915-98c633140000 pid=5171->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=5bd9c487-1900-0000-4915-98c642140000 pid=5186->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=553c0d8c-1900-0000-4915-98c663140000 pid=5219 /usr/bin/bash guuid=a715f68b-1900-0000-4915-98c662140000 pid=5218->guuid=553c0d8c-1900-0000-4915-98c663140000 pid=5219 clone guuid=8bf4b88c-1900-0000-4915-98c668140000 pid=5224->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=b4d7218f-1900-0000-4915-98c66a140000 pid=5226->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=308f8f93-1900-0000-4915-98c66d140000 pid=5229 /usr/bin/bash guuid=751a7193-1900-0000-4915-98c66c140000 pid=5228->guuid=308f8f93-1900-0000-4915-98c66d140000 pid=5229 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3e4748230fb13db23696117efea3b5db43b95d1d6da5c2e08078531ed61cac21

(this sample)

  
Delivery method
Distributed via web download

Comments