MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6546db8a603850dac69b0110bcb9a9d54db837e28dfa2cf04da6b6242f65d719. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 6546db8a603850dac69b0110bcb9a9d54db837e28dfa2cf04da6b6242f65d719
SHA3-384 hash: 980b6d6b1e6703759750468825390eb4597a9196a9920126b3619c8be705de3de819f31fc967c7e120608e86c2a0045a
SHA1 hash: 3475e18a44843a507a75200be832d5ac853e4a7f
MD5 hash: c149f66075c59582d99d869ddd6b1505
humanhash: nuts-double-minnesota-yellow
File name:nig.sh
Download: download sample
Signature Gafgyt
File size:1'148 bytes
First seen:2025-07-28 20:22:05 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:sEUSIbK5zOt+MB0Ei4wghBh9Mk8Qoy3Z1kksepkS:sEUXK5CEA0Ei4wghL8Qo4ZCkVkS
TLSH T139211ECD9291CC309CA01CDAF2C36405E84BD7D96FD74C84B589A17AB46CD0871A1F7A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.51.126.131/k/mipsdc09b912cad01060375273eb113736c6ad7b8fba16e573d5d1792014cf6b7d04 Gafgytelf gafgyt opendir ua-wget
http://158.51.126.131/k/mipseld0ec2c47dffa30456847ff6c1ca0c1e3a3666f3c1306775821f8e7891058e731 Gafgytelf gafgyt opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=842689f9-1a00-0000-815f-827b890c0000 pid=3209 /usr/bin/sudo guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210 /tmp/sample.bin guuid=842689f9-1a00-0000-815f-827b890c0000 pid=3209->guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210 execve guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211 clone guuid=b25c9bfd-1a00-0000-815f-827b910c0000 pid=3217 /usr/bin/rm delete-file guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b25c9bfd-1a00-0000-815f-827b910c0000 pid=3217 execve guuid=cc9706fe-1a00-0000-815f-827b920c0000 pid=3218 /usr/bin/rm delete-file guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=cc9706fe-1a00-0000-815f-827b920c0000 pid=3218 execve guuid=fa3b96fe-1a00-0000-815f-827b930c0000 pid=3219 /usr/bin/rm delete-file guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=fa3b96fe-1a00-0000-815f-827b930c0000 pid=3219 execve guuid=7b4c09ff-1a00-0000-815f-827b940c0000 pid=3220 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=7b4c09ff-1a00-0000-815f-827b940c0000 pid=3220 clone guuid=7106faff-1a00-0000-815f-827b960c0000 pid=3222 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=7106faff-1a00-0000-815f-827b960c0000 pid=3222 clone guuid=0f5e7500-1b00-0000-815f-827b980c0000 pid=3224 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=0f5e7500-1b00-0000-815f-827b980c0000 pid=3224 execve guuid=540f0701-1b00-0000-815f-827b9a0c0000 pid=3226 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=540f0701-1b00-0000-815f-827b9a0c0000 pid=3226 execve guuid=8fab8c01-1b00-0000-815f-827b9b0c0000 pid=3227 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=8fab8c01-1b00-0000-815f-827b9b0c0000 pid=3227 execve guuid=35a30202-1b00-0000-815f-827b9c0c0000 pid=3228 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=35a30202-1b00-0000-815f-827b9c0c0000 pid=3228 execve guuid=c73b8102-1b00-0000-815f-827b9e0c0000 pid=3230 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c73b8102-1b00-0000-815f-827b9e0c0000 pid=3230 execve guuid=0663f202-1b00-0000-815f-827ba00c0000 pid=3232 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=0663f202-1b00-0000-815f-827ba00c0000 pid=3232 execve guuid=487e5303-1b00-0000-815f-827ba20c0000 pid=3234 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=487e5303-1b00-0000-815f-827ba20c0000 pid=3234 execve guuid=4e88b503-1b00-0000-815f-827ba40c0000 pid=3236 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=4e88b503-1b00-0000-815f-827ba40c0000 pid=3236 execve guuid=4a621604-1b00-0000-815f-827ba70c0000 pid=3239 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=4a621604-1b00-0000-815f-827ba70c0000 pid=3239 execve guuid=9d197304-1b00-0000-815f-827ba80c0000 pid=3240 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=9d197304-1b00-0000-815f-827ba80c0000 pid=3240 execve guuid=f263d704-1b00-0000-815f-827baa0c0000 pid=3242 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=f263d704-1b00-0000-815f-827baa0c0000 pid=3242 execve guuid=b8835705-1b00-0000-815f-827bab0c0000 pid=3243 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b8835705-1b00-0000-815f-827bab0c0000 pid=3243 execve guuid=a6b3cd05-1b00-0000-815f-827bac0c0000 pid=3244 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a6b3cd05-1b00-0000-815f-827bac0c0000 pid=3244 execve guuid=16bf3f06-1b00-0000-815f-827bad0c0000 pid=3245 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=16bf3f06-1b00-0000-815f-827bad0c0000 pid=3245 execve guuid=909cb106-1b00-0000-815f-827bb00c0000 pid=3248 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=909cb106-1b00-0000-815f-827bb00c0000 pid=3248 execve guuid=c7c31c07-1b00-0000-815f-827bb20c0000 pid=3250 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c7c31c07-1b00-0000-815f-827bb20c0000 pid=3250 execve guuid=d4bf8607-1b00-0000-815f-827bb50c0000 pid=3253 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=d4bf8607-1b00-0000-815f-827bb50c0000 pid=3253 execve guuid=c133eb07-1b00-0000-815f-827bb70c0000 pid=3255 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c133eb07-1b00-0000-815f-827bb70c0000 pid=3255 execve guuid=e2cd4d08-1b00-0000-815f-827bb80c0000 pid=3256 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=e2cd4d08-1b00-0000-815f-827bb80c0000 pid=3256 execve guuid=8237ae08-1b00-0000-815f-827bba0c0000 pid=3258 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=8237ae08-1b00-0000-815f-827bba0c0000 pid=3258 execve guuid=0c821509-1b00-0000-815f-827bbb0c0000 pid=3259 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=0c821509-1b00-0000-815f-827bbb0c0000 pid=3259 execve guuid=a5967809-1b00-0000-815f-827bbd0c0000 pid=3261 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a5967809-1b00-0000-815f-827bbd0c0000 pid=3261 execve guuid=a7f6e109-1b00-0000-815f-827bbf0c0000 pid=3263 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a7f6e109-1b00-0000-815f-827bbf0c0000 pid=3263 execve guuid=097d430a-1b00-0000-815f-827bc10c0000 pid=3265 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=097d430a-1b00-0000-815f-827bc10c0000 pid=3265 execve guuid=b878dc0a-1b00-0000-815f-827bc40c0000 pid=3268 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b878dc0a-1b00-0000-815f-827bc40c0000 pid=3268 execve guuid=390a490b-1b00-0000-815f-827bc60c0000 pid=3270 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=390a490b-1b00-0000-815f-827bc60c0000 pid=3270 execve guuid=b1d6000c-1b00-0000-815f-827bc70c0000 pid=3271 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b1d6000c-1b00-0000-815f-827bc70c0000 pid=3271 execve guuid=ee63c70c-1b00-0000-815f-827bc80c0000 pid=3272 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=ee63c70c-1b00-0000-815f-827bc80c0000 pid=3272 execve guuid=f382690d-1b00-0000-815f-827bc90c0000 pid=3273 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=f382690d-1b00-0000-815f-827bc90c0000 pid=3273 execve guuid=251e000e-1b00-0000-815f-827bca0c0000 pid=3274 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=251e000e-1b00-0000-815f-827bca0c0000 pid=3274 execve guuid=b9c1c50e-1b00-0000-815f-827bcb0c0000 pid=3275 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b9c1c50e-1b00-0000-815f-827bcb0c0000 pid=3275 execve guuid=762eb00f-1b00-0000-815f-827bcc0c0000 pid=3276 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=762eb00f-1b00-0000-815f-827bcc0c0000 pid=3276 execve guuid=41c94810-1b00-0000-815f-827bcd0c0000 pid=3277 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=41c94810-1b00-0000-815f-827bcd0c0000 pid=3277 execve guuid=e66cd510-1b00-0000-815f-827bce0c0000 pid=3278 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=e66cd510-1b00-0000-815f-827bce0c0000 pid=3278 execve guuid=db2e5111-1b00-0000-815f-827bd00c0000 pid=3280 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=db2e5111-1b00-0000-815f-827bd00c0000 pid=3280 execve guuid=d9d6d811-1b00-0000-815f-827bd10c0000 pid=3281 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=d9d6d811-1b00-0000-815f-827bd10c0000 pid=3281 execve guuid=e78c5912-1b00-0000-815f-827bd20c0000 pid=3282 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=e78c5912-1b00-0000-815f-827bd20c0000 pid=3282 execve guuid=501bcd12-1b00-0000-815f-827bd40c0000 pid=3284 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=501bcd12-1b00-0000-815f-827bd40c0000 pid=3284 execve guuid=a8665413-1b00-0000-815f-827bd70c0000 pid=3287 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a8665413-1b00-0000-815f-827bd70c0000 pid=3287 execve guuid=360ed313-1b00-0000-815f-827bd80c0000 pid=3288 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=360ed313-1b00-0000-815f-827bd80c0000 pid=3288 execve guuid=79345f14-1b00-0000-815f-827bdb0c0000 pid=3291 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=79345f14-1b00-0000-815f-827bdb0c0000 pid=3291 execve guuid=2043f714-1b00-0000-815f-827bdd0c0000 pid=3293 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=2043f714-1b00-0000-815f-827bdd0c0000 pid=3293 execve guuid=3b136e15-1b00-0000-815f-827bdf0c0000 pid=3295 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=3b136e15-1b00-0000-815f-827bdf0c0000 pid=3295 execve guuid=1697e415-1b00-0000-815f-827be00c0000 pid=3296 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=1697e415-1b00-0000-815f-827be00c0000 pid=3296 execve guuid=91215316-1b00-0000-815f-827be20c0000 pid=3298 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=91215316-1b00-0000-815f-827be20c0000 pid=3298 execve guuid=0773ee16-1b00-0000-815f-827be50c0000 pid=3301 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=0773ee16-1b00-0000-815f-827be50c0000 pid=3301 execve guuid=b7f49217-1b00-0000-815f-827be80c0000 pid=3304 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b7f49217-1b00-0000-815f-827be80c0000 pid=3304 execve guuid=ab152f18-1b00-0000-815f-827bea0c0000 pid=3306 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=ab152f18-1b00-0000-815f-827bea0c0000 pid=3306 execve guuid=5472b418-1b00-0000-815f-827bec0c0000 pid=3308 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=5472b418-1b00-0000-815f-827bec0c0000 pid=3308 execve guuid=a4203019-1b00-0000-815f-827bee0c0000 pid=3310 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a4203019-1b00-0000-815f-827bee0c0000 pid=3310 execve guuid=66adb519-1b00-0000-815f-827bf10c0000 pid=3313 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=66adb519-1b00-0000-815f-827bf10c0000 pid=3313 execve guuid=b5c4341a-1b00-0000-815f-827bf40c0000 pid=3316 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b5c4341a-1b00-0000-815f-827bf40c0000 pid=3316 execve guuid=908aa21a-1b00-0000-815f-827bf60c0000 pid=3318 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=908aa21a-1b00-0000-815f-827bf60c0000 pid=3318 execve guuid=7ceb971b-1b00-0000-815f-827bf70c0000 pid=3319 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=7ceb971b-1b00-0000-815f-827bf70c0000 pid=3319 execve guuid=34a3991c-1b00-0000-815f-827bf80c0000 pid=3320 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=34a3991c-1b00-0000-815f-827bf80c0000 pid=3320 execve guuid=c095971d-1b00-0000-815f-827bf90c0000 pid=3321 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c095971d-1b00-0000-815f-827bf90c0000 pid=3321 execve guuid=746e851e-1b00-0000-815f-827bfa0c0000 pid=3322 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=746e851e-1b00-0000-815f-827bfa0c0000 pid=3322 execve guuid=371c5e1f-1b00-0000-815f-827bfc0c0000 pid=3324 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=371c5e1f-1b00-0000-815f-827bfc0c0000 pid=3324 execve guuid=4285df1f-1b00-0000-815f-827bfd0c0000 pid=3325 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=4285df1f-1b00-0000-815f-827bfd0c0000 pid=3325 execve guuid=2cd25e20-1b00-0000-815f-827bfe0c0000 pid=3326 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=2cd25e20-1b00-0000-815f-827bfe0c0000 pid=3326 execve guuid=f311cd20-1b00-0000-815f-827b000d0000 pid=3328 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=f311cd20-1b00-0000-815f-827b000d0000 pid=3328 execve guuid=87933921-1b00-0000-815f-827b020d0000 pid=3330 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=87933921-1b00-0000-815f-827b020d0000 pid=3330 execve guuid=8d14b921-1b00-0000-815f-827b040d0000 pid=3332 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=8d14b921-1b00-0000-815f-827b040d0000 pid=3332 execve guuid=4e082f22-1b00-0000-815f-827b060d0000 pid=3334 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=4e082f22-1b00-0000-815f-827b060d0000 pid=3334 execve guuid=3c0a9822-1b00-0000-815f-827b090d0000 pid=3337 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=3c0a9822-1b00-0000-815f-827b090d0000 pid=3337 execve guuid=73542823-1b00-0000-815f-827b0b0d0000 pid=3339 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=73542823-1b00-0000-815f-827b0b0d0000 pid=3339 execve guuid=07a79c23-1b00-0000-815f-827b0d0d0000 pid=3341 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=07a79c23-1b00-0000-815f-827b0d0d0000 pid=3341 execve guuid=0fb30c24-1b00-0000-815f-827b0f0d0000 pid=3343 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=0fb30c24-1b00-0000-815f-827b0f0d0000 pid=3343 execve guuid=b5297724-1b00-0000-815f-827b110d0000 pid=3345 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b5297724-1b00-0000-815f-827b110d0000 pid=3345 execve guuid=157ecf24-1b00-0000-815f-827b130d0000 pid=3347 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=157ecf24-1b00-0000-815f-827b130d0000 pid=3347 execve guuid=8f112925-1b00-0000-815f-827b150d0000 pid=3349 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=8f112925-1b00-0000-815f-827b150d0000 pid=3349 execve guuid=eaa4a025-1b00-0000-815f-827b180d0000 pid=3352 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=eaa4a025-1b00-0000-815f-827b180d0000 pid=3352 execve guuid=13d30826-1b00-0000-815f-827b1b0d0000 pid=3355 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=13d30826-1b00-0000-815f-827b1b0d0000 pid=3355 execve guuid=a03cfa26-1b00-0000-815f-827b1e0d0000 pid=3358 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a03cfa26-1b00-0000-815f-827b1e0d0000 pid=3358 execve guuid=73636b27-1b00-0000-815f-827b200d0000 pid=3360 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=73636b27-1b00-0000-815f-827b200d0000 pid=3360 execve guuid=720a3928-1b00-0000-815f-827b210d0000 pid=3361 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=720a3928-1b00-0000-815f-827b210d0000 pid=3361 execve guuid=071bf228-1b00-0000-815f-827b230d0000 pid=3363 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=071bf228-1b00-0000-815f-827b230d0000 pid=3363 execve guuid=7547ac29-1b00-0000-815f-827b250d0000 pid=3365 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=7547ac29-1b00-0000-815f-827b250d0000 pid=3365 execve guuid=9a774e2a-1b00-0000-815f-827b280d0000 pid=3368 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=9a774e2a-1b00-0000-815f-827b280d0000 pid=3368 execve guuid=a0f0f42a-1b00-0000-815f-827b2b0d0000 pid=3371 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a0f0f42a-1b00-0000-815f-827b2b0d0000 pid=3371 execve guuid=01e8982b-1b00-0000-815f-827b2e0d0000 pid=3374 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=01e8982b-1b00-0000-815f-827b2e0d0000 pid=3374 execve guuid=40a30f2c-1b00-0000-815f-827b310d0000 pid=3377 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=40a30f2c-1b00-0000-815f-827b310d0000 pid=3377 execve guuid=2056842c-1b00-0000-815f-827b330d0000 pid=3379 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=2056842c-1b00-0000-815f-827b330d0000 pid=3379 execve guuid=dc65172d-1b00-0000-815f-827b360d0000 pid=3382 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=dc65172d-1b00-0000-815f-827b360d0000 pid=3382 execve guuid=f133b52d-1b00-0000-815f-827b390d0000 pid=3385 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=f133b52d-1b00-0000-815f-827b390d0000 pid=3385 execve guuid=8c1f5c2e-1b00-0000-815f-827b3c0d0000 pid=3388 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=8c1f5c2e-1b00-0000-815f-827b3c0d0000 pid=3388 execve guuid=2b33fa2e-1b00-0000-815f-827b3e0d0000 pid=3390 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=2b33fa2e-1b00-0000-815f-827b3e0d0000 pid=3390 execve guuid=2b8c572f-1b00-0000-815f-827b400d0000 pid=3392 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=2b8c572f-1b00-0000-815f-827b400d0000 pid=3392 execve guuid=9fcdbb2f-1b00-0000-815f-827b410d0000 pid=3393 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=9fcdbb2f-1b00-0000-815f-827b410d0000 pid=3393 execve guuid=c8181730-1b00-0000-815f-827b430d0000 pid=3395 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c8181730-1b00-0000-815f-827b430d0000 pid=3395 execve guuid=4db9bb30-1b00-0000-815f-827b450d0000 pid=3397 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=4db9bb30-1b00-0000-815f-827b450d0000 pid=3397 execve guuid=25528631-1b00-0000-815f-827b470d0000 pid=3399 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=25528631-1b00-0000-815f-827b470d0000 pid=3399 execve guuid=3b3f2d32-1b00-0000-815f-827b4b0d0000 pid=3403 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=3b3f2d32-1b00-0000-815f-827b4b0d0000 pid=3403 execve guuid=f3879b32-1b00-0000-815f-827b4c0d0000 pid=3404 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=f3879b32-1b00-0000-815f-827b4c0d0000 pid=3404 execve guuid=46ae3e33-1b00-0000-815f-827b4e0d0000 pid=3406 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=46ae3e33-1b00-0000-815f-827b4e0d0000 pid=3406 execve guuid=33523b34-1b00-0000-815f-827b4f0d0000 pid=3407 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=33523b34-1b00-0000-815f-827b4f0d0000 pid=3407 execve guuid=4601c934-1b00-0000-815f-827b500d0000 pid=3408 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=4601c934-1b00-0000-815f-827b500d0000 pid=3408 execve guuid=e3333335-1b00-0000-815f-827b520d0000 pid=3410 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=e3333335-1b00-0000-815f-827b520d0000 pid=3410 execve guuid=2badaf35-1b00-0000-815f-827b550d0000 pid=3413 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=2badaf35-1b00-0000-815f-827b550d0000 pid=3413 execve guuid=e54e0b36-1b00-0000-815f-827b570d0000 pid=3415 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=e54e0b36-1b00-0000-815f-827b570d0000 pid=3415 execve guuid=3daf7f36-1b00-0000-815f-827b5a0d0000 pid=3418 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=3daf7f36-1b00-0000-815f-827b5a0d0000 pid=3418 execve guuid=bd05eb36-1b00-0000-815f-827b5c0d0000 pid=3420 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=bd05eb36-1b00-0000-815f-827b5c0d0000 pid=3420 execve guuid=822b6437-1b00-0000-815f-827b5e0d0000 pid=3422 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=822b6437-1b00-0000-815f-827b5e0d0000 pid=3422 execve guuid=78251138-1b00-0000-815f-827b620d0000 pid=3426 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=78251138-1b00-0000-815f-827b620d0000 pid=3426 execve guuid=5ed6b138-1b00-0000-815f-827b640d0000 pid=3428 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=5ed6b138-1b00-0000-815f-827b640d0000 pid=3428 execve guuid=b1b68939-1b00-0000-815f-827b670d0000 pid=3431 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=b1b68939-1b00-0000-815f-827b670d0000 pid=3431 execve guuid=6a84303a-1b00-0000-815f-827b6b0d0000 pid=3435 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=6a84303a-1b00-0000-815f-827b6b0d0000 pid=3435 execve guuid=7e83553b-1b00-0000-815f-827b6e0d0000 pid=3438 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=7e83553b-1b00-0000-815f-827b6e0d0000 pid=3438 execve guuid=ad6aff3b-1b00-0000-815f-827b6f0d0000 pid=3439 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=ad6aff3b-1b00-0000-815f-827b6f0d0000 pid=3439 execve guuid=9f54c13c-1b00-0000-815f-827b700d0000 pid=3440 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=9f54c13c-1b00-0000-815f-827b700d0000 pid=3440 execve guuid=7aa43c3d-1b00-0000-815f-827b730d0000 pid=3443 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=7aa43c3d-1b00-0000-815f-827b730d0000 pid=3443 execve guuid=d908bc3d-1b00-0000-815f-827b750d0000 pid=3445 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=d908bc3d-1b00-0000-815f-827b750d0000 pid=3445 execve guuid=c88b313e-1b00-0000-815f-827b780d0000 pid=3448 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c88b313e-1b00-0000-815f-827b780d0000 pid=3448 execve guuid=6059a23e-1b00-0000-815f-827b7a0d0000 pid=3450 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=6059a23e-1b00-0000-815f-827b7a0d0000 pid=3450 execve guuid=a43b013f-1b00-0000-815f-827b7b0d0000 pid=3451 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a43b013f-1b00-0000-815f-827b7b0d0000 pid=3451 execve guuid=fe36833f-1b00-0000-815f-827b7c0d0000 pid=3452 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=fe36833f-1b00-0000-815f-827b7c0d0000 pid=3452 execve guuid=932e0240-1b00-0000-815f-827b7d0d0000 pid=3453 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=932e0240-1b00-0000-815f-827b7d0d0000 pid=3453 execve guuid=0dc97e40-1b00-0000-815f-827b7e0d0000 pid=3454 /usr/bin/ls guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=0dc97e40-1b00-0000-815f-827b7e0d0000 pid=3454 execve guuid=e0d13b4d-1b00-0000-815f-827b850d0000 pid=3461 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=e0d13b4d-1b00-0000-815f-827b850d0000 pid=3461 clone guuid=c3a6eb81-1b00-0000-815f-827bee0d0000 pid=3566 /usr/bin/chmod guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=c3a6eb81-1b00-0000-815f-827bee0d0000 pid=3566 execve guuid=18442782-1b00-0000-815f-827bef0d0000 pid=3567 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=18442782-1b00-0000-815f-827bef0d0000 pid=3567 clone guuid=a826c282-1b00-0000-815f-827bf20d0000 pid=3570 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=a826c282-1b00-0000-815f-827bf20d0000 pid=3570 clone guuid=d12dd1b6-1b00-0000-815f-827b4e0e0000 pid=3662 /usr/bin/chmod guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=d12dd1b6-1b00-0000-815f-827b4e0e0000 pid=3662 execve guuid=fc3a3ab7-1b00-0000-815f-827b4f0e0000 pid=3663 /usr/bin/dash guuid=7b34b0fb-1a00-0000-815f-827b8a0c0000 pid=3210->guuid=fc3a3ab7-1b00-0000-815f-827b4f0e0000 pid=3663 clone guuid=ea131ffc-1a00-0000-815f-827b8c0c0000 pid=3212 /usr/bin/cat guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211->guuid=ea131ffc-1a00-0000-815f-827b8c0c0000 pid=3212 execve guuid=018e29fc-1a00-0000-815f-827b8d0c0000 pid=3213 /usr/bin/grep guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211->guuid=018e29fc-1a00-0000-815f-827b8d0c0000 pid=3213 execve guuid=ead432fc-1a00-0000-815f-827b8e0c0000 pid=3214 /usr/bin/grep guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211->guuid=ead432fc-1a00-0000-815f-827b8e0c0000 pid=3214 execve guuid=240f3afc-1a00-0000-815f-827b8f0c0000 pid=3215 /usr/bin/grep guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211->guuid=240f3afc-1a00-0000-815f-827b8f0c0000 pid=3215 execve guuid=10ea44fc-1a00-0000-815f-827b900c0000 pid=3216 /usr/bin/cut guuid=fc860dfc-1a00-0000-815f-827b8b0c0000 pid=3211->guuid=10ea44fc-1a00-0000-815f-827b900c0000 pid=3216 execve guuid=05511dff-1a00-0000-815f-827b950c0000 pid=3221 /usr/bin/cp write-file guuid=7b4c09ff-1a00-0000-815f-827b940c0000 pid=3220->guuid=05511dff-1a00-0000-815f-827b950c0000 pid=3221 execve guuid=bc0b0a00-1b00-0000-815f-827b970c0000 pid=3223 /usr/bin/chmod guuid=7106faff-1a00-0000-815f-827b960c0000 pid=3222->guuid=bc0b0a00-1b00-0000-815f-827b970c0000 pid=3223 execve guuid=ad8e4e4d-1b00-0000-815f-827b860d0000 pid=3462 /usr/bin/wget net send-data write-file guuid=e0d13b4d-1b00-0000-815f-827b850d0000 pid=3461->guuid=ad8e4e4d-1b00-0000-815f-827b860d0000 pid=3462 execve 2beca644-24da-5e18-bc49-c06b8c4a111d 158.51.126.131:80 guuid=ad8e4e4d-1b00-0000-815f-827b860d0000 pid=3462->2beca644-24da-5e18-bc49-c06b8c4a111d send: 135B guuid=048cc882-1b00-0000-815f-827bf30d0000 pid=3571 /usr/bin/wget net send-data write-file guuid=a826c282-1b00-0000-815f-827bf20d0000 pid=3570->guuid=048cc882-1b00-0000-815f-827bf30d0000 pid=3571 execve guuid=048cc882-1b00-0000-815f-827bf30d0000 pid=3571->2beca644-24da-5e18-bc49-c06b8c4a111d send: 137B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Malgent
Status:
Malicious
First seen:
2025-07-28 20:22:24 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 6546db8a603850dac69b0110bcb9a9d54db837e28dfa2cf04da6b6242f65d719

(this sample)

  
Delivery method
Distributed via web download

Comments