MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43a2c3e869bcf8fc9e90732bdc3a85f949c854fc2e80bda5598bf8474c64bfa2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 43a2c3e869bcf8fc9e90732bdc3a85f949c854fc2e80bda5598bf8474c64bfa2
SHA3-384 hash: cf6fb987414dc5df89580ba6c2c1dfae737aa60dce96acb55b6753f789350f86a154a2a7b7ea3a1d02cff9915d6a6c49
SHA1 hash: 47462dbbe84922c521eea22bc75c759659515acf
MD5 hash: 99dd97786a34107a71a8e395a8a7cd50
humanhash: bulldog-social-november-hamper
File name:ok
Download: download sample
File size:1'608 bytes
First seen:2026-06-10 08:43:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:InVbRQubMtn4dENycKcqgsHR9pHBOsijUJyaYZjU5Z:InQhtn4QQOgiQ
TLSH T1D931D4AB171E3AAC5405E9A97360155CD094E6EA304FE3A0FB880C7BE2D95583219F8F
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/e354dfn/an/aelf ua-wget
http://45.205.1.59/4b708fn/an/aelf ua-wget
http://45.205.1.59/404c5en/an/aelf ua-wget
http://45.205.1.59/dca252n/an/aelf ua-wget
http://45.205.1.59/db9316n/an/aelf ua-wget
http://45.205.1.59/fad9fen/an/aelf ua-wget
http://45.205.1.59/29ede0n/an/aelf ua-wget
http://45.205.1.59/b62386n/an/aelf ua-wget
http://45.205.1.59/572dacn/an/aelf ua-wget
http://45.205.1.59/2ad9f8n/an/aelf ua-wget
http://45.205.1.59/fe9a4fn/an/aelf ua-wget
http://45.205.1.59/67dbbcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=d10bdb3c-1700-0000-b2c3-e137b00d0000 pid=3504 /usr/bin/sudo guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509 /tmp/sample.bin guuid=d10bdb3c-1700-0000-b2c3-e137b00d0000 pid=3504->guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509 execve guuid=961d293f-1700-0000-b2c3-e137b80d0000 pid=3512 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=961d293f-1700-0000-b2c3-e137b80d0000 pid=3512 execve guuid=80801f59-1700-0000-b2c3-e1370c0e0000 pid=3596 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=80801f59-1700-0000-b2c3-e1370c0e0000 pid=3596 execve guuid=f2751c76-1700-0000-b2c3-e137600e0000 pid=3680 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=f2751c76-1700-0000-b2c3-e137600e0000 pid=3680 execve guuid=6a0a7b76-1700-0000-b2c3-e137620e0000 pid=3682 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=6a0a7b76-1700-0000-b2c3-e137620e0000 pid=3682 clone guuid=292bb176-1700-0000-b2c3-e137640e0000 pid=3684 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=292bb176-1700-0000-b2c3-e137640e0000 pid=3684 execve guuid=5d6ff276-1700-0000-b2c3-e137660e0000 pid=3686 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=5d6ff276-1700-0000-b2c3-e137660e0000 pid=3686 execve guuid=8a643677-1700-0000-b2c3-e137680e0000 pid=3688 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=8a643677-1700-0000-b2c3-e137680e0000 pid=3688 execve guuid=52f84391-1700-0000-b2c3-e137c30e0000 pid=3779 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=52f84391-1700-0000-b2c3-e137c30e0000 pid=3779 execve guuid=2e7418ac-1700-0000-b2c3-e1372a0f0000 pid=3882 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=2e7418ac-1700-0000-b2c3-e1372a0f0000 pid=3882 execve guuid=ccc3ceac-1700-0000-b2c3-e1372b0f0000 pid=3883 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=ccc3ceac-1700-0000-b2c3-e1372b0f0000 pid=3883 clone guuid=899e41ad-1700-0000-b2c3-e1372f0f0000 pid=3887 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=899e41ad-1700-0000-b2c3-e1372f0f0000 pid=3887 execve guuid=709a9bad-1700-0000-b2c3-e137300f0000 pid=3888 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=709a9bad-1700-0000-b2c3-e137300f0000 pid=3888 execve guuid=09a3e9ad-1700-0000-b2c3-e137320f0000 pid=3890 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=09a3e9ad-1700-0000-b2c3-e137320f0000 pid=3890 execve guuid=3d0231c8-1700-0000-b2c3-e1379e0f0000 pid=3998 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=3d0231c8-1700-0000-b2c3-e1379e0f0000 pid=3998 execve guuid=8c66a4e4-1700-0000-b2c3-e137f60f0000 pid=4086 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=8c66a4e4-1700-0000-b2c3-e137f60f0000 pid=4086 execve guuid=b0dbebe4-1700-0000-b2c3-e137f80f0000 pid=4088 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=b0dbebe4-1700-0000-b2c3-e137f80f0000 pid=4088 clone guuid=f7782be5-1700-0000-b2c3-e137fb0f0000 pid=4091 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=f7782be5-1700-0000-b2c3-e137fb0f0000 pid=4091 execve guuid=6d8e73e5-1700-0000-b2c3-e137fc0f0000 pid=4092 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=6d8e73e5-1700-0000-b2c3-e137fc0f0000 pid=4092 execve guuid=46f3b5e5-1700-0000-b2c3-e137fe0f0000 pid=4094 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=46f3b5e5-1700-0000-b2c3-e137fe0f0000 pid=4094 execve guuid=17865900-1800-0000-b2c3-e1373c100000 pid=4156 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=17865900-1800-0000-b2c3-e1373c100000 pid=4156 execve guuid=115c301d-1800-0000-b2c3-e13790100000 pid=4240 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=115c301d-1800-0000-b2c3-e13790100000 pid=4240 execve guuid=e546931d-1800-0000-b2c3-e13792100000 pid=4242 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=e546931d-1800-0000-b2c3-e13792100000 pid=4242 clone guuid=6b8e1d1e-1800-0000-b2c3-e13797100000 pid=4247 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=6b8e1d1e-1800-0000-b2c3-e13797100000 pid=4247 execve guuid=8de26a1e-1800-0000-b2c3-e1379b100000 pid=4251 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=8de26a1e-1800-0000-b2c3-e1379b100000 pid=4251 execve guuid=46a9a91e-1800-0000-b2c3-e1379c100000 pid=4252 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=46a9a91e-1800-0000-b2c3-e1379c100000 pid=4252 execve guuid=169d0838-1800-0000-b2c3-e137fb100000 pid=4347 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=169d0838-1800-0000-b2c3-e137fb100000 pid=4347 execve guuid=4cc8d653-1800-0000-b2c3-e13755110000 pid=4437 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=4cc8d653-1800-0000-b2c3-e13755110000 pid=4437 execve guuid=e7885c54-1800-0000-b2c3-e13757110000 pid=4439 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=e7885c54-1800-0000-b2c3-e13757110000 pid=4439 clone guuid=abc59854-1800-0000-b2c3-e1375a110000 pid=4442 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=abc59854-1800-0000-b2c3-e1375a110000 pid=4442 execve guuid=0106df54-1800-0000-b2c3-e1375c110000 pid=4444 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=0106df54-1800-0000-b2c3-e1375c110000 pid=4444 execve guuid=b4232155-1800-0000-b2c3-e1375d110000 pid=4445 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=b4232155-1800-0000-b2c3-e1375d110000 pid=4445 execve guuid=d4c2176f-1800-0000-b2c3-e137ba110000 pid=4538 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=d4c2176f-1800-0000-b2c3-e137ba110000 pid=4538 execve guuid=4e67448b-1800-0000-b2c3-e13737120000 pid=4663 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=4e67448b-1800-0000-b2c3-e13737120000 pid=4663 execve guuid=bbdebc8b-1800-0000-b2c3-e13738120000 pid=4664 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=bbdebc8b-1800-0000-b2c3-e13738120000 pid=4664 clone guuid=5c2e218c-1800-0000-b2c3-e1373b120000 pid=4667 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=5c2e218c-1800-0000-b2c3-e1373b120000 pid=4667 execve guuid=396d688c-1800-0000-b2c3-e1373d120000 pid=4669 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=396d688c-1800-0000-b2c3-e1373d120000 pid=4669 execve guuid=9065b38c-1800-0000-b2c3-e1373f120000 pid=4671 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=9065b38c-1800-0000-b2c3-e1373f120000 pid=4671 execve guuid=681ca7a6-1800-0000-b2c3-e137a8120000 pid=4776 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=681ca7a6-1800-0000-b2c3-e137a8120000 pid=4776 execve guuid=82eb7cc3-1800-0000-b2c3-e13709130000 pid=4873 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=82eb7cc3-1800-0000-b2c3-e13709130000 pid=4873 execve guuid=1c51c0c3-1800-0000-b2c3-e1370b130000 pid=4875 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=1c51c0c3-1800-0000-b2c3-e1370b130000 pid=4875 clone guuid=fcc3fac3-1800-0000-b2c3-e1370e130000 pid=4878 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=fcc3fac3-1800-0000-b2c3-e1370e130000 pid=4878 execve guuid=314171c4-1800-0000-b2c3-e13710130000 pid=4880 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=314171c4-1800-0000-b2c3-e13710130000 pid=4880 execve guuid=e5f7b9c4-1800-0000-b2c3-e13713130000 pid=4883 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=e5f7b9c4-1800-0000-b2c3-e13713130000 pid=4883 execve guuid=1a5ce4de-1800-0000-b2c3-e13765130000 pid=4965 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=1a5ce4de-1800-0000-b2c3-e13765130000 pid=4965 execve guuid=6d8b77fa-1800-0000-b2c3-e1379d130000 pid=5021 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=6d8b77fa-1800-0000-b2c3-e1379d130000 pid=5021 execve guuid=c87ef7fa-1800-0000-b2c3-e1379e130000 pid=5022 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=c87ef7fa-1800-0000-b2c3-e1379e130000 pid=5022 clone guuid=2c7b73fb-1800-0000-b2c3-e137a1130000 pid=5025 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=2c7b73fb-1800-0000-b2c3-e137a1130000 pid=5025 execve guuid=d516e5fb-1800-0000-b2c3-e137a3130000 pid=5027 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=d516e5fb-1800-0000-b2c3-e137a3130000 pid=5027 execve guuid=e41d61fc-1800-0000-b2c3-e137a5130000 pid=5029 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=e41d61fc-1800-0000-b2c3-e137a5130000 pid=5029 execve guuid=0c21b617-1900-0000-b2c3-e137e7130000 pid=5095 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=0c21b617-1900-0000-b2c3-e137e7130000 pid=5095 execve guuid=d9417234-1900-0000-b2c3-e13738140000 pid=5176 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=d9417234-1900-0000-b2c3-e13738140000 pid=5176 execve guuid=2b4d0935-1900-0000-b2c3-e1373a140000 pid=5178 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=2b4d0935-1900-0000-b2c3-e1373a140000 pid=5178 clone guuid=29f17a35-1900-0000-b2c3-e1373d140000 pid=5181 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=29f17a35-1900-0000-b2c3-e1373d140000 pid=5181 execve guuid=767a0c36-1900-0000-b2c3-e1373f140000 pid=5183 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=767a0c36-1900-0000-b2c3-e1373f140000 pid=5183 execve guuid=9b7b8636-1900-0000-b2c3-e13741140000 pid=5185 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=9b7b8636-1900-0000-b2c3-e13741140000 pid=5185 execve guuid=6db7b850-1900-0000-b2c3-e13776140000 pid=5238 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=6db7b850-1900-0000-b2c3-e13776140000 pid=5238 execve guuid=9189d36c-1900-0000-b2c3-e1379c140000 pid=5276 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=9189d36c-1900-0000-b2c3-e1379c140000 pid=5276 execve guuid=3013526d-1900-0000-b2c3-e1379d140000 pid=5277 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=3013526d-1900-0000-b2c3-e1379d140000 pid=5277 clone guuid=61489c6d-1900-0000-b2c3-e1379f140000 pid=5279 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=61489c6d-1900-0000-b2c3-e1379f140000 pid=5279 execve guuid=9f96f26d-1900-0000-b2c3-e137a0140000 pid=5280 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=9f96f26d-1900-0000-b2c3-e137a0140000 pid=5280 execve guuid=262c4b6e-1900-0000-b2c3-e137a1140000 pid=5281 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=262c4b6e-1900-0000-b2c3-e137a1140000 pid=5281 execve guuid=ace2a988-1900-0000-b2c3-e137ad140000 pid=5293 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=ace2a988-1900-0000-b2c3-e137ad140000 pid=5293 execve guuid=b4fda5a4-1900-0000-b2c3-e137ae140000 pid=5294 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=b4fda5a4-1900-0000-b2c3-e137ae140000 pid=5294 execve guuid=5fd5f6a4-1900-0000-b2c3-e137af140000 pid=5295 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=5fd5f6a4-1900-0000-b2c3-e137af140000 pid=5295 clone guuid=29a534a5-1900-0000-b2c3-e137b1140000 pid=5297 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=29a534a5-1900-0000-b2c3-e137b1140000 pid=5297 execve guuid=1fb789a5-1900-0000-b2c3-e137b2140000 pid=5298 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=1fb789a5-1900-0000-b2c3-e137b2140000 pid=5298 execve guuid=99cce5a5-1900-0000-b2c3-e137b3140000 pid=5299 /usr/bin/wget net send-data guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=99cce5a5-1900-0000-b2c3-e137b3140000 pid=5299 execve guuid=b7ba95bf-1900-0000-b2c3-e137b4140000 pid=5300 /usr/bin/curl net send-data write-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=b7ba95bf-1900-0000-b2c3-e137b4140000 pid=5300 execve guuid=cea284da-1900-0000-b2c3-e137b5140000 pid=5301 /usr/bin/chmod guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=cea284da-1900-0000-b2c3-e137b5140000 pid=5301 execve guuid=27f4d3da-1900-0000-b2c3-e137b6140000 pid=5302 /usr/bin/bash guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=27f4d3da-1900-0000-b2c3-e137b6140000 pid=5302 clone guuid=01b331db-1900-0000-b2c3-e137b8140000 pid=5304 /usr/bin/rm delete-file guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=01b331db-1900-0000-b2c3-e137b8140000 pid=5304 execve guuid=db9e7edb-1900-0000-b2c3-e137b9140000 pid=5305 /usr/bin/rm guuid=439bcf3e-1700-0000-b2c3-e137b50d0000 pid=3509->guuid=db9e7edb-1900-0000-b2c3-e137b9140000 pid=5305 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=961d293f-1700-0000-b2c3-e137b80d0000 pid=3512->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=80801f59-1700-0000-b2c3-e1370c0e0000 pid=3596->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=a27d9576-1700-0000-b2c3-e137630e0000 pid=3683 /usr/bin/bash guuid=6a0a7b76-1700-0000-b2c3-e137620e0000 pid=3682->guuid=a27d9576-1700-0000-b2c3-e137630e0000 pid=3683 clone guuid=8a643677-1700-0000-b2c3-e137680e0000 pid=3688->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=52f84391-1700-0000-b2c3-e137c30e0000 pid=3779->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=f04decac-1700-0000-b2c3-e1372d0f0000 pid=3885 /usr/bin/bash guuid=ccc3ceac-1700-0000-b2c3-e1372b0f0000 pid=3883->guuid=f04decac-1700-0000-b2c3-e1372d0f0000 pid=3885 clone guuid=09a3e9ad-1700-0000-b2c3-e137320f0000 pid=3890->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=3d0231c8-1700-0000-b2c3-e1379e0f0000 pid=3998->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=62ce04e5-1700-0000-b2c3-e137f90f0000 pid=4089 /usr/bin/bash guuid=b0dbebe4-1700-0000-b2c3-e137f80f0000 pid=4088->guuid=62ce04e5-1700-0000-b2c3-e137f90f0000 pid=4089 clone guuid=46f3b5e5-1700-0000-b2c3-e137fe0f0000 pid=4094->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=17865900-1800-0000-b2c3-e1373c100000 pid=4156->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=6508ed1d-1800-0000-b2c3-e13796100000 pid=4246 /usr/bin/bash guuid=e546931d-1800-0000-b2c3-e13792100000 pid=4242->guuid=6508ed1d-1800-0000-b2c3-e13796100000 pid=4246 clone guuid=46a9a91e-1800-0000-b2c3-e1379c100000 pid=4252->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=169d0838-1800-0000-b2c3-e137fb100000 pid=4347->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=13a97a54-1800-0000-b2c3-e13759110000 pid=4441 /usr/bin/bash guuid=e7885c54-1800-0000-b2c3-e13757110000 pid=4439->guuid=13a97a54-1800-0000-b2c3-e13759110000 pid=4441 clone guuid=b4232155-1800-0000-b2c3-e1375d110000 pid=4445->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=d4c2176f-1800-0000-b2c3-e137ba110000 pid=4538->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=6123e28b-1800-0000-b2c3-e13739120000 pid=4665 /usr/bin/bash guuid=bbdebc8b-1800-0000-b2c3-e13738120000 pid=4664->guuid=6123e28b-1800-0000-b2c3-e13739120000 pid=4665 clone guuid=9065b38c-1800-0000-b2c3-e1373f120000 pid=4671->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=681ca7a6-1800-0000-b2c3-e137a8120000 pid=4776->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=96bfdbc3-1800-0000-b2c3-e1370c130000 pid=4876 /usr/bin/bash guuid=1c51c0c3-1800-0000-b2c3-e1370b130000 pid=4875->guuid=96bfdbc3-1800-0000-b2c3-e1370c130000 pid=4876 clone guuid=e5f7b9c4-1800-0000-b2c3-e13713130000 pid=4883->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=1a5ce4de-1800-0000-b2c3-e13765130000 pid=4965->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=c59322fb-1800-0000-b2c3-e137a0130000 pid=5024 /usr/bin/bash guuid=c87ef7fa-1800-0000-b2c3-e1379e130000 pid=5022->guuid=c59322fb-1800-0000-b2c3-e137a0130000 pid=5024 clone guuid=e41d61fc-1800-0000-b2c3-e137a5130000 pid=5029->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=0c21b617-1900-0000-b2c3-e137e7130000 pid=5095->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=9c724135-1900-0000-b2c3-e1373b140000 pid=5179 /usr/bin/bash guuid=2b4d0935-1900-0000-b2c3-e1373a140000 pid=5178->guuid=9c724135-1900-0000-b2c3-e1373b140000 pid=5179 clone guuid=9b7b8636-1900-0000-b2c3-e13741140000 pid=5185->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=6db7b850-1900-0000-b2c3-e13776140000 pid=5238->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=5f676f6d-1900-0000-b2c3-e1379e140000 pid=5278 /usr/bin/bash guuid=3013526d-1900-0000-b2c3-e1379d140000 pid=5277->guuid=5f676f6d-1900-0000-b2c3-e1379e140000 pid=5278 clone guuid=262c4b6e-1900-0000-b2c3-e137a1140000 pid=5281->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=ace2a988-1900-0000-b2c3-e137ad140000 pid=5293->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=cbbd15a5-1900-0000-b2c3-e137b0140000 pid=5296 /usr/bin/bash guuid=5fd5f6a4-1900-0000-b2c3-e137af140000 pid=5295->guuid=cbbd15a5-1900-0000-b2c3-e137b0140000 pid=5296 clone guuid=99cce5a5-1900-0000-b2c3-e137b3140000 pid=5299->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b7ba95bf-1900-0000-b2c3-e137b4140000 pid=5300->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4506f5da-1900-0000-b2c3-e137b7140000 pid=5303 /usr/bin/bash guuid=27f4d3da-1900-0000-b2c3-e137b6140000 pid=5302->guuid=4506f5da-1900-0000-b2c3-e137b7140000 pid=5303 clone
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 43a2c3e869bcf8fc9e90732bdc3a85f949c854fc2e80bda5598bf8474c64bfa2

(this sample)

  
Delivery method
Distributed via web download

Comments