MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5feb26de5895690dc911c4e6a714f67f185cef3508d8833bc0e390cc8a1debbf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5feb26de5895690dc911c4e6a714f67f185cef3508d8833bc0e390cc8a1debbf
SHA3-384 hash: ab754cc55637fce78cf50de53c131539ca796132b71c92c3596ea819690768bf0046d1b0fa83e568561e29ae0472e1bf
SHA1 hash: 2cd4ff93660d2b8a1739c395312d3fd2940c5847
MD5 hash: bbb16f431b37b8d639137755877461b8
humanhash: uncle-saturn-winner-romeo
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-06 13:43:37 UTC
Last seen:2026-06-06 16:52:09 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaOzJiq7BAEvwYpG7:e9Qp+MsOkkGEvwYpG7
TLSH T11001ABCEC022DA208196E89D62E7A1807824C3CB66464FED7F8C043EDFADB687015FC4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/VoXdn/an/an/a
http://188.132.232.81/8V4sn/an/an/a
http://188.132.232.81/V41n/an/an/a
http://188.132.232.81/MTkZn/an/an/a
http://188.132.232.81/cEen/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=66a334f1-1700-0000-970d-a77a5a0b0000 pid=2906 /usr/bin/sudo guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910 /tmp/sample.bin write-file guuid=66a334f1-1700-0000-970d-a77a5a0b0000 pid=2906->guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910 execve guuid=d1152af3-1700-0000-970d-a77a600b0000 pid=2912 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=d1152af3-1700-0000-970d-a77a600b0000 pid=2912 execve guuid=d4b88ef3-1700-0000-970d-a77a620b0000 pid=2914 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=d4b88ef3-1700-0000-970d-a77a620b0000 pid=2914 execve guuid=dc78f1f3-1700-0000-970d-a77a640b0000 pid=2916 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=dc78f1f3-1700-0000-970d-a77a640b0000 pid=2916 execve guuid=c0c451f4-1700-0000-970d-a77a660b0000 pid=2918 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c0c451f4-1700-0000-970d-a77a660b0000 pid=2918 execve guuid=d3f1b4f4-1700-0000-970d-a77a680b0000 pid=2920 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=d3f1b4f4-1700-0000-970d-a77a680b0000 pid=2920 execve guuid=46f20ff5-1700-0000-970d-a77a6a0b0000 pid=2922 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=46f20ff5-1700-0000-970d-a77a6a0b0000 pid=2922 execve guuid=ac966df5-1700-0000-970d-a77a6c0b0000 pid=2924 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=ac966df5-1700-0000-970d-a77a6c0b0000 pid=2924 execve guuid=a503d1f5-1700-0000-970d-a77a6d0b0000 pid=2925 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=a503d1f5-1700-0000-970d-a77a6d0b0000 pid=2925 execve guuid=610c5af6-1700-0000-970d-a77a6e0b0000 pid=2926 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=610c5af6-1700-0000-970d-a77a6e0b0000 pid=2926 execve guuid=bc75e1f6-1700-0000-970d-a77a6f0b0000 pid=2927 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=bc75e1f6-1700-0000-970d-a77a6f0b0000 pid=2927 execve guuid=71a87bf7-1700-0000-970d-a77a700b0000 pid=2928 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=71a87bf7-1700-0000-970d-a77a700b0000 pid=2928 execve guuid=2f687cf8-1700-0000-970d-a77a710b0000 pid=2929 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=2f687cf8-1700-0000-970d-a77a710b0000 pid=2929 execve guuid=563234f9-1700-0000-970d-a77a730b0000 pid=2931 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=563234f9-1700-0000-970d-a77a730b0000 pid=2931 execve guuid=853aa9f9-1700-0000-970d-a77a740b0000 pid=2932 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=853aa9f9-1700-0000-970d-a77a740b0000 pid=2932 execve guuid=b1ab05fa-1700-0000-970d-a77a760b0000 pid=2934 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b1ab05fa-1700-0000-970d-a77a760b0000 pid=2934 execve guuid=13c46efa-1700-0000-970d-a77a780b0000 pid=2936 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=13c46efa-1700-0000-970d-a77a780b0000 pid=2936 execve guuid=4e07d3fa-1700-0000-970d-a77a7a0b0000 pid=2938 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=4e07d3fa-1700-0000-970d-a77a7a0b0000 pid=2938 execve guuid=9bdb36fb-1700-0000-970d-a77a7d0b0000 pid=2941 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=9bdb36fb-1700-0000-970d-a77a7d0b0000 pid=2941 execve guuid=606196fb-1700-0000-970d-a77a7f0b0000 pid=2943 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=606196fb-1700-0000-970d-a77a7f0b0000 pid=2943 execve guuid=f36a0bfc-1700-0000-970d-a77a800b0000 pid=2944 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f36a0bfc-1700-0000-970d-a77a800b0000 pid=2944 execve guuid=8dbe8efc-1700-0000-970d-a77a810b0000 pid=2945 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=8dbe8efc-1700-0000-970d-a77a810b0000 pid=2945 execve guuid=b6a20afd-1700-0000-970d-a77a820b0000 pid=2946 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b6a20afd-1700-0000-970d-a77a820b0000 pid=2946 execve guuid=082371fd-1700-0000-970d-a77a840b0000 pid=2948 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=082371fd-1700-0000-970d-a77a840b0000 pid=2948 execve guuid=c1cffafd-1700-0000-970d-a77a850b0000 pid=2949 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c1cffafd-1700-0000-970d-a77a850b0000 pid=2949 execve guuid=1bdd7dfe-1700-0000-970d-a77a860b0000 pid=2950 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=1bdd7dfe-1700-0000-970d-a77a860b0000 pid=2950 execve guuid=e84febfe-1700-0000-970d-a77a880b0000 pid=2952 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e84febfe-1700-0000-970d-a77a880b0000 pid=2952 execve guuid=dd4c50ff-1700-0000-970d-a77a8a0b0000 pid=2954 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=dd4c50ff-1700-0000-970d-a77a8a0b0000 pid=2954 execve guuid=5a5dcaff-1700-0000-970d-a77a8c0b0000 pid=2956 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=5a5dcaff-1700-0000-970d-a77a8c0b0000 pid=2956 execve guuid=1c312e00-1800-0000-970d-a77a8d0b0000 pid=2957 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=1c312e00-1800-0000-970d-a77a8d0b0000 pid=2957 execve guuid=6b5a8b00-1800-0000-970d-a77a8f0b0000 pid=2959 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=6b5a8b00-1800-0000-970d-a77a8f0b0000 pid=2959 execve guuid=f8bbf000-1800-0000-970d-a77a910b0000 pid=2961 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f8bbf000-1800-0000-970d-a77a910b0000 pid=2961 execve guuid=31315601-1800-0000-970d-a77a930b0000 pid=2963 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=31315601-1800-0000-970d-a77a930b0000 pid=2963 execve guuid=bcc8cc01-1800-0000-970d-a77a940b0000 pid=2964 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=bcc8cc01-1800-0000-970d-a77a940b0000 pid=2964 execve guuid=02874e02-1800-0000-970d-a77a950b0000 pid=2965 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=02874e02-1800-0000-970d-a77a950b0000 pid=2965 execve guuid=8fa1a702-1800-0000-970d-a77a970b0000 pid=2967 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=8fa1a702-1800-0000-970d-a77a970b0000 pid=2967 execve guuid=f6480a03-1800-0000-970d-a77a990b0000 pid=2969 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f6480a03-1800-0000-970d-a77a990b0000 pid=2969 execve guuid=86bc6d03-1800-0000-970d-a77a9c0b0000 pid=2972 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=86bc6d03-1800-0000-970d-a77a9c0b0000 pid=2972 execve guuid=830ad403-1800-0000-970d-a77a9e0b0000 pid=2974 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=830ad403-1800-0000-970d-a77a9e0b0000 pid=2974 execve guuid=69143804-1800-0000-970d-a77aa00b0000 pid=2976 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=69143804-1800-0000-970d-a77aa00b0000 pid=2976 execve guuid=d8e19f04-1800-0000-970d-a77aa20b0000 pid=2978 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=d8e19f04-1800-0000-970d-a77aa20b0000 pid=2978 execve guuid=c1a01105-1800-0000-970d-a77aa30b0000 pid=2979 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c1a01105-1800-0000-970d-a77aa30b0000 pid=2979 execve guuid=c1e68205-1800-0000-970d-a77aa50b0000 pid=2981 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c1e68205-1800-0000-970d-a77aa50b0000 pid=2981 execve guuid=ac42f905-1800-0000-970d-a77aa60b0000 pid=2982 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=ac42f905-1800-0000-970d-a77aa60b0000 pid=2982 execve guuid=847a7306-1800-0000-970d-a77aa70b0000 pid=2983 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=847a7306-1800-0000-970d-a77aa70b0000 pid=2983 execve guuid=86b0e606-1800-0000-970d-a77aa80b0000 pid=2984 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=86b0e606-1800-0000-970d-a77aa80b0000 pid=2984 execve guuid=bcd14007-1800-0000-970d-a77aa90b0000 pid=2985 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=bcd14007-1800-0000-970d-a77aa90b0000 pid=2985 execve guuid=2d2ea107-1800-0000-970d-a77aac0b0000 pid=2988 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=2d2ea107-1800-0000-970d-a77aac0b0000 pid=2988 execve guuid=41d70408-1800-0000-970d-a77aae0b0000 pid=2990 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=41d70408-1800-0000-970d-a77aae0b0000 pid=2990 execve guuid=f4fd7008-1800-0000-970d-a77ab10b0000 pid=2993 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f4fd7008-1800-0000-970d-a77ab10b0000 pid=2993 execve guuid=c321e208-1800-0000-970d-a77ab30b0000 pid=2995 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c321e208-1800-0000-970d-a77ab30b0000 pid=2995 execve guuid=91ad5409-1800-0000-970d-a77ab60b0000 pid=2998 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=91ad5409-1800-0000-970d-a77ab60b0000 pid=2998 execve guuid=5a10d209-1800-0000-970d-a77ab80b0000 pid=3000 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=5a10d209-1800-0000-970d-a77ab80b0000 pid=3000 execve guuid=011d7d0a-1800-0000-970d-a77ab90b0000 pid=3001 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=011d7d0a-1800-0000-970d-a77ab90b0000 pid=3001 execve guuid=dbd9f20a-1800-0000-970d-a77abb0b0000 pid=3003 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=dbd9f20a-1800-0000-970d-a77abb0b0000 pid=3003 execve guuid=7118690b-1800-0000-970d-a77abe0b0000 pid=3006 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=7118690b-1800-0000-970d-a77abe0b0000 pid=3006 execve guuid=f04ccf0b-1800-0000-970d-a77ac00b0000 pid=3008 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f04ccf0b-1800-0000-970d-a77ac00b0000 pid=3008 execve guuid=43c45f0c-1800-0000-970d-a77ac30b0000 pid=3011 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=43c45f0c-1800-0000-970d-a77ac30b0000 pid=3011 execve guuid=b4b1040d-1800-0000-970d-a77ac60b0000 pid=3014 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b4b1040d-1800-0000-970d-a77ac60b0000 pid=3014 execve guuid=69c7bf0d-1800-0000-970d-a77ac80b0000 pid=3016 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=69c7bf0d-1800-0000-970d-a77ac80b0000 pid=3016 execve guuid=9be7570e-1800-0000-970d-a77ac90b0000 pid=3017 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=9be7570e-1800-0000-970d-a77ac90b0000 pid=3017 execve guuid=a4d6fc0e-1800-0000-970d-a77acd0b0000 pid=3021 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=a4d6fc0e-1800-0000-970d-a77acd0b0000 pid=3021 execve guuid=4e607e0f-1800-0000-970d-a77acf0b0000 pid=3023 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=4e607e0f-1800-0000-970d-a77acf0b0000 pid=3023 execve guuid=a7671e10-1800-0000-970d-a77ad20b0000 pid=3026 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=a7671e10-1800-0000-970d-a77ad20b0000 pid=3026 execve guuid=10b7c510-1800-0000-970d-a77ad40b0000 pid=3028 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=10b7c510-1800-0000-970d-a77ad40b0000 pid=3028 execve guuid=e0ca4f11-1800-0000-970d-a77ad60b0000 pid=3030 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e0ca4f11-1800-0000-970d-a77ad60b0000 pid=3030 execve guuid=3028d311-1800-0000-970d-a77ad70b0000 pid=3031 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3028d311-1800-0000-970d-a77ad70b0000 pid=3031 execve guuid=c1fe4c12-1800-0000-970d-a77ad90b0000 pid=3033 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c1fe4c12-1800-0000-970d-a77ad90b0000 pid=3033 execve guuid=6571d312-1800-0000-970d-a77ada0b0000 pid=3034 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=6571d312-1800-0000-970d-a77ada0b0000 pid=3034 execve guuid=14b55613-1800-0000-970d-a77adb0b0000 pid=3035 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=14b55613-1800-0000-970d-a77adb0b0000 pid=3035 execve guuid=c6d4ca13-1800-0000-970d-a77adc0b0000 pid=3036 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=c6d4ca13-1800-0000-970d-a77adc0b0000 pid=3036 execve guuid=3f7e4514-1800-0000-970d-a77ade0b0000 pid=3038 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3f7e4514-1800-0000-970d-a77ade0b0000 pid=3038 execve guuid=e892ac14-1800-0000-970d-a77ae00b0000 pid=3040 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e892ac14-1800-0000-970d-a77ae00b0000 pid=3040 execve guuid=d9f00f15-1800-0000-970d-a77ae20b0000 pid=3042 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=d9f00f15-1800-0000-970d-a77ae20b0000 pid=3042 execve guuid=53107615-1800-0000-970d-a77ae40b0000 pid=3044 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=53107615-1800-0000-970d-a77ae40b0000 pid=3044 execve guuid=dc41d915-1800-0000-970d-a77ae60b0000 pid=3046 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=dc41d915-1800-0000-970d-a77ae60b0000 pid=3046 execve guuid=21e73416-1800-0000-970d-a77ae80b0000 pid=3048 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=21e73416-1800-0000-970d-a77ae80b0000 pid=3048 execve guuid=01fb9516-1800-0000-970d-a77aea0b0000 pid=3050 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=01fb9516-1800-0000-970d-a77aea0b0000 pid=3050 execve guuid=3d120817-1800-0000-970d-a77aec0b0000 pid=3052 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3d120817-1800-0000-970d-a77aec0b0000 pid=3052 execve guuid=eca36917-1800-0000-970d-a77aee0b0000 pid=3054 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=eca36917-1800-0000-970d-a77aee0b0000 pid=3054 execve guuid=e3761a18-1800-0000-970d-a77af20b0000 pid=3058 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e3761a18-1800-0000-970d-a77af20b0000 pid=3058 execve guuid=22e37718-1800-0000-970d-a77af40b0000 pid=3060 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=22e37718-1800-0000-970d-a77af40b0000 pid=3060 execve guuid=3385d218-1800-0000-970d-a77af70b0000 pid=3063 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3385d218-1800-0000-970d-a77af70b0000 pid=3063 execve guuid=48e04a19-1800-0000-970d-a77af90b0000 pid=3065 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=48e04a19-1800-0000-970d-a77af90b0000 pid=3065 execve guuid=031cbf19-1800-0000-970d-a77afc0b0000 pid=3068 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=031cbf19-1800-0000-970d-a77afc0b0000 pid=3068 execve guuid=1a0f311a-1800-0000-970d-a77afe0b0000 pid=3070 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=1a0f311a-1800-0000-970d-a77afe0b0000 pid=3070 execve guuid=3a34a21a-1800-0000-970d-a77aff0b0000 pid=3071 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3a34a21a-1800-0000-970d-a77aff0b0000 pid=3071 execve guuid=040c101b-1800-0000-970d-a77a010c0000 pid=3073 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=040c101b-1800-0000-970d-a77a010c0000 pid=3073 execve guuid=e08c7a1b-1800-0000-970d-a77a040c0000 pid=3076 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e08c7a1b-1800-0000-970d-a77a040c0000 pid=3076 execve guuid=0756dd1b-1800-0000-970d-a77a060c0000 pid=3078 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=0756dd1b-1800-0000-970d-a77a060c0000 pid=3078 execve guuid=ba244b1c-1800-0000-970d-a77a080c0000 pid=3080 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=ba244b1c-1800-0000-970d-a77a080c0000 pid=3080 execve guuid=b280b81c-1800-0000-970d-a77a0b0c0000 pid=3083 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b280b81c-1800-0000-970d-a77a0b0c0000 pid=3083 execve guuid=3e081e1d-1800-0000-970d-a77a0d0c0000 pid=3085 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3e081e1d-1800-0000-970d-a77a0d0c0000 pid=3085 execve guuid=f883881d-1800-0000-970d-a77a100c0000 pid=3088 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f883881d-1800-0000-970d-a77a100c0000 pid=3088 execve guuid=f86ffa1d-1800-0000-970d-a77a120c0000 pid=3090 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f86ffa1d-1800-0000-970d-a77a120c0000 pid=3090 execve guuid=7d517d1e-1800-0000-970d-a77a130c0000 pid=3091 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=7d517d1e-1800-0000-970d-a77a130c0000 pid=3091 execve guuid=3df5f71e-1800-0000-970d-a77a140c0000 pid=3092 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=3df5f71e-1800-0000-970d-a77a140c0000 pid=3092 execve guuid=0f7d781f-1800-0000-970d-a77a160c0000 pid=3094 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=0f7d781f-1800-0000-970d-a77a160c0000 pid=3094 execve guuid=8573d41f-1800-0000-970d-a77a180c0000 pid=3096 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=8573d41f-1800-0000-970d-a77a180c0000 pid=3096 execve guuid=f42b2c20-1800-0000-970d-a77a1a0c0000 pid=3098 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f42b2c20-1800-0000-970d-a77a1a0c0000 pid=3098 execve guuid=9ce7d820-1800-0000-970d-a77a1d0c0000 pid=3101 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=9ce7d820-1800-0000-970d-a77a1d0c0000 pid=3101 execve guuid=2c5f3c21-1800-0000-970d-a77a200c0000 pid=3104 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=2c5f3c21-1800-0000-970d-a77a200c0000 pid=3104 execve guuid=54f1a921-1800-0000-970d-a77a220c0000 pid=3106 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=54f1a921-1800-0000-970d-a77a220c0000 pid=3106 execve guuid=2f000422-1800-0000-970d-a77a250c0000 pid=3109 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=2f000422-1800-0000-970d-a77a250c0000 pid=3109 execve guuid=6b046d22-1800-0000-970d-a77a260c0000 pid=3110 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=6b046d22-1800-0000-970d-a77a260c0000 pid=3110 execve guuid=a00bd522-1800-0000-970d-a77a270c0000 pid=3111 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=a00bd522-1800-0000-970d-a77a270c0000 pid=3111 execve guuid=e1726123-1800-0000-970d-a77a280c0000 pid=3112 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e1726123-1800-0000-970d-a77a280c0000 pid=3112 execve guuid=41e22124-1800-0000-970d-a77a290c0000 pid=3113 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=41e22124-1800-0000-970d-a77a290c0000 pid=3113 execve guuid=e0be9324-1800-0000-970d-a77a2a0c0000 pid=3114 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e0be9324-1800-0000-970d-a77a2a0c0000 pid=3114 execve guuid=0ab81b25-1800-0000-970d-a77a2b0c0000 pid=3115 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=0ab81b25-1800-0000-970d-a77a2b0c0000 pid=3115 execve guuid=cd7e9525-1800-0000-970d-a77a2c0c0000 pid=3116 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=cd7e9525-1800-0000-970d-a77a2c0c0000 pid=3116 execve guuid=e7892d26-1800-0000-970d-a77a2d0c0000 pid=3117 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e7892d26-1800-0000-970d-a77a2d0c0000 pid=3117 execve guuid=a6f1b926-1800-0000-970d-a77a2e0c0000 pid=3118 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=a6f1b926-1800-0000-970d-a77a2e0c0000 pid=3118 execve guuid=8db54527-1800-0000-970d-a77a2f0c0000 pid=3119 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=8db54527-1800-0000-970d-a77a2f0c0000 pid=3119 execve guuid=1e09d827-1800-0000-970d-a77a300c0000 pid=3120 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=1e09d827-1800-0000-970d-a77a300c0000 pid=3120 execve guuid=13b56728-1800-0000-970d-a77a310c0000 pid=3121 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=13b56728-1800-0000-970d-a77a310c0000 pid=3121 execve guuid=fe75f428-1800-0000-970d-a77a320c0000 pid=3122 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=fe75f428-1800-0000-970d-a77a320c0000 pid=3122 execve guuid=97ca6c29-1800-0000-970d-a77a330c0000 pid=3123 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=97ca6c29-1800-0000-970d-a77a330c0000 pid=3123 execve guuid=284cf229-1800-0000-970d-a77a340c0000 pid=3124 /usr/bin/ls guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=284cf229-1800-0000-970d-a77a340c0000 pid=3124 execve guuid=a21a712a-1800-0000-970d-a77a350c0000 pid=3125 /usr/bin/rm guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=a21a712a-1800-0000-970d-a77a350c0000 pid=3125 execve guuid=b8aad02a-1800-0000-970d-a77a360c0000 pid=3126 /usr/bin/wget net send-data write-file guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b8aad02a-1800-0000-970d-a77a360c0000 pid=3126 execve guuid=b03247e6-1800-0000-970d-a77a300d0000 pid=3376 /usr/bin/chmod guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b03247e6-1800-0000-970d-a77a300d0000 pid=3376 execve guuid=f722a8e6-1800-0000-970d-a77a330d0000 pid=3379 /usr/bin/dash guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=f722a8e6-1800-0000-970d-a77a330d0000 pid=3379 clone guuid=aa798ee8-1800-0000-970d-a77a3a0d0000 pid=3386 /usr/bin/rm guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=aa798ee8-1800-0000-970d-a77a3a0d0000 pid=3386 execve guuid=e999dbe8-1800-0000-970d-a77a3c0d0000 pid=3388 /usr/bin/wget net send-data write-file guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=e999dbe8-1800-0000-970d-a77a3c0d0000 pid=3388 execve guuid=9286e78d-1900-0000-970d-a77a8b0e0000 pid=3723 /usr/bin/chmod guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=9286e78d-1900-0000-970d-a77a8b0e0000 pid=3723 execve guuid=d0a9228e-1900-0000-970d-a77a8c0e0000 pid=3724 /usr/bin/dash guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=d0a9228e-1900-0000-970d-a77a8c0e0000 pid=3724 clone guuid=4449ca8e-1900-0000-970d-a77a8e0e0000 pid=3726 /usr/bin/rm guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=4449ca8e-1900-0000-970d-a77a8e0e0000 pid=3726 execve guuid=ccd65e8f-1900-0000-970d-a77a900e0000 pid=3728 /usr/bin/wget net send-data write-file guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=ccd65e8f-1900-0000-970d-a77a900e0000 pid=3728 execve guuid=fa2dd67b-1a00-0000-970d-a77a20110000 pid=4384 /usr/bin/chmod guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=fa2dd67b-1a00-0000-970d-a77a20110000 pid=4384 execve guuid=713e307c-1a00-0000-970d-a77a23110000 pid=4387 /usr/bin/dash guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=713e307c-1a00-0000-970d-a77a23110000 pid=4387 clone guuid=939a047d-1a00-0000-970d-a77a27110000 pid=4391 /usr/bin/rm guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=939a047d-1a00-0000-970d-a77a27110000 pid=4391 execve guuid=ef8d647d-1a00-0000-970d-a77a29110000 pid=4393 /usr/bin/wget net send-data write-file guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=ef8d647d-1a00-0000-970d-a77a29110000 pid=4393 execve guuid=cf6dc146-1c00-0000-970d-a77aee140000 pid=5358 /usr/bin/chmod guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=cf6dc146-1c00-0000-970d-a77aee140000 pid=5358 execve guuid=4eaa0a47-1c00-0000-970d-a77aef140000 pid=5359 /usr/bin/dash guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=4eaa0a47-1c00-0000-970d-a77aef140000 pid=5359 clone guuid=4de21448-1c00-0000-970d-a77af1140000 pid=5361 /usr/bin/rm guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=4de21448-1c00-0000-970d-a77af1140000 pid=5361 execve guuid=39345c48-1c00-0000-970d-a77af2140000 pid=5362 /usr/bin/wget net send-data write-file guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=39345c48-1c00-0000-970d-a77af2140000 pid=5362 execve guuid=b4da4e53-1e00-0000-970d-a77a0a150000 pid=5386 /usr/bin/chmod guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=b4da4e53-1e00-0000-970d-a77a0a150000 pid=5386 execve guuid=16448e53-1e00-0000-970d-a77a0b150000 pid=5387 /usr/bin/dash guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=16448e53-1e00-0000-970d-a77a0b150000 pid=5387 clone guuid=1cee5554-1e00-0000-970d-a77a0d150000 pid=5389 /usr/bin/rm delete-file guuid=665bf8f2-1700-0000-970d-a77a5e0b0000 pid=2910->guuid=1cee5554-1e00-0000-970d-a77a0d150000 pid=5389 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=b8aad02a-1800-0000-970d-a77a360c0000 pid=3126->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=e999dbe8-1800-0000-970d-a77a3c0d0000 pid=3388->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=ccd65e8f-1900-0000-970d-a77a900e0000 pid=3728->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=ef8d647d-1a00-0000-970d-a77a29110000 pid=4393->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=39345c48-1c00-0000-970d-a77af2140000 pid=5362->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-06 13:44:42 UTC
File Type:
Text (Shell)
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5feb26de5895690dc911c4e6a714f67f185cef3508d8833bc0e390cc8a1debbf

(this sample)

  
Delivery method
Distributed via web download

Comments