MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71e947d830bdb4f9aec4b6dbdf36cd04222791defbced6f489800acee3eeed15. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 71e947d830bdb4f9aec4b6dbdf36cd04222791defbced6f489800acee3eeed15
SHA3-384 hash: a1c9507ad089446e6f621afe316600c679fd7b4467335e0e4eadfb4795f3e701f890a6f655d6fdc8912b901bef3f354e
SHA1 hash: de2811cd58f8201582828010f27800d6e2c4e98c
MD5 hash: f2602d2024f852fa967ddcb75ca89c44
humanhash: sink-coffee-high-east
File name:ok
Download: download sample
File size:1'620 bytes
First seen:2026-06-11 03:09:08 UTC
Last seen:2026-06-11 23:30:40 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:YEmarcu/EwEUBS2425pblote/o/yh7lr/kHpkY+Ne0EQvmcbgAJl9O:Bm0kxo/ZaHmY+00EQvmcBO
TLSH T15731C4BB0B1D764E1202DEA9B7762648E410E5CA204FE794FB1C08BDA2CD54A311BE0B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/b77984n/an/aelf ua-wget
http://45.205.1.59/d1489dn/an/aelf ua-wget
http://45.205.1.59/1cbafdn/an/aelf ua-wget
http://45.205.1.59/5bc63bn/an/aelf ua-wget
http://45.205.1.59/6cd3afn/an/aelf ua-wget
http://45.205.1.59/8c085bn/an/aelf ua-wget
http://45.205.1.59/fd832an/an/aelf ua-wget
http://45.205.1.59/8e8625n/an/aelf ua-wget
http://45.205.1.59/2dca37n/an/aelf ua-wget
http://45.205.1.59/e7fb51n/an/aelf ua-wget
http://45.205.1.59/f57bc8n/an/aelf ua-wget
http://45.205.1.59/2be1a2n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-11T00:16:00Z UTC
Last seen:
2026-06-11T02:35:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9c88cc2e-1700-0000-a3d6-3508620e0000 pid=3682 /usr/bin/sudo guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690 /tmp/sample.bin guuid=9c88cc2e-1700-0000-a3d6-3508620e0000 pid=3682->guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690 execve guuid=8a22c430-1700-0000-a3d6-35086d0e0000 pid=3693 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=8a22c430-1700-0000-a3d6-35086d0e0000 pid=3693 execve guuid=a765294b-1700-0000-a3d6-3508e00e0000 pid=3808 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=a765294b-1700-0000-a3d6-3508e00e0000 pid=3808 execve guuid=26c6df67-1700-0000-a3d6-35083d0f0000 pid=3901 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=26c6df67-1700-0000-a3d6-35083d0f0000 pid=3901 execve guuid=53105568-1700-0000-a3d6-35083f0f0000 pid=3903 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=53105568-1700-0000-a3d6-35083f0f0000 pid=3903 clone guuid=9916cb68-1700-0000-a3d6-3508420f0000 pid=3906 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=9916cb68-1700-0000-a3d6-3508420f0000 pid=3906 execve guuid=777c3b69-1700-0000-a3d6-3508440f0000 pid=3908 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=777c3b69-1700-0000-a3d6-3508440f0000 pid=3908 execve guuid=92eea969-1700-0000-a3d6-3508450f0000 pid=3909 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=92eea969-1700-0000-a3d6-3508450f0000 pid=3909 execve guuid=11915584-1700-0000-a3d6-35088b0f0000 pid=3979 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=11915584-1700-0000-a3d6-35088b0f0000 pid=3979 execve guuid=dfe943a2-1700-0000-a3d6-3508f10f0000 pid=4081 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=dfe943a2-1700-0000-a3d6-3508f10f0000 pid=4081 execve guuid=c4ea7da2-1700-0000-a3d6-3508f30f0000 pid=4083 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=c4ea7da2-1700-0000-a3d6-3508f30f0000 pid=4083 clone guuid=945fafa2-1700-0000-a3d6-3508f60f0000 pid=4086 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=945fafa2-1700-0000-a3d6-3508f60f0000 pid=4086 execve guuid=b3a5f2a2-1700-0000-a3d6-3508f70f0000 pid=4087 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=b3a5f2a2-1700-0000-a3d6-3508f70f0000 pid=4087 execve guuid=e93d2ea3-1700-0000-a3d6-3508f90f0000 pid=4089 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=e93d2ea3-1700-0000-a3d6-3508f90f0000 pid=4089 execve guuid=8c4a54bd-1700-0000-a3d6-350841100000 pid=4161 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=8c4a54bd-1700-0000-a3d6-350841100000 pid=4161 execve guuid=d9b889da-1700-0000-a3d6-3508a1100000 pid=4257 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=d9b889da-1700-0000-a3d6-3508a1100000 pid=4257 execve guuid=2d28feda-1700-0000-a3d6-3508a3100000 pid=4259 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=2d28feda-1700-0000-a3d6-3508a3100000 pid=4259 clone guuid=5e206ddb-1700-0000-a3d6-3508a5100000 pid=4261 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=5e206ddb-1700-0000-a3d6-3508a5100000 pid=4261 execve guuid=ba45e1db-1700-0000-a3d6-3508a7100000 pid=4263 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=ba45e1db-1700-0000-a3d6-3508a7100000 pid=4263 execve guuid=e73049dc-1700-0000-a3d6-3508ab100000 pid=4267 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=e73049dc-1700-0000-a3d6-3508ab100000 pid=4267 execve guuid=906c56f7-1700-0000-a3d6-3508ee100000 pid=4334 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=906c56f7-1700-0000-a3d6-3508ee100000 pid=4334 execve guuid=37aaec14-1800-0000-a3d6-350846110000 pid=4422 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=37aaec14-1800-0000-a3d6-350846110000 pid=4422 execve guuid=6f795015-1800-0000-a3d6-350848110000 pid=4424 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=6f795015-1800-0000-a3d6-350848110000 pid=4424 clone guuid=3f779515-1800-0000-a3d6-35084b110000 pid=4427 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=3f779515-1800-0000-a3d6-35084b110000 pid=4427 execve guuid=7cacdd15-1800-0000-a3d6-35084f110000 pid=4431 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=7cacdd15-1800-0000-a3d6-35084f110000 pid=4431 execve guuid=82322616-1800-0000-a3d6-350850110000 pid=4432 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=82322616-1800-0000-a3d6-350850110000 pid=4432 execve guuid=8434bd30-1800-0000-a3d6-3508a6110000 pid=4518 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=8434bd30-1800-0000-a3d6-3508a6110000 pid=4518 execve guuid=569b8b4e-1800-0000-a3d6-35081d120000 pid=4637 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=569b8b4e-1800-0000-a3d6-35081d120000 pid=4637 execve guuid=f219d24e-1800-0000-a3d6-35081e120000 pid=4638 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=f219d24e-1800-0000-a3d6-35081e120000 pid=4638 clone guuid=27c1094f-1800-0000-a3d6-350821120000 pid=4641 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=27c1094f-1800-0000-a3d6-350821120000 pid=4641 execve guuid=4986534f-1800-0000-a3d6-350822120000 pid=4642 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=4986534f-1800-0000-a3d6-350822120000 pid=4642 execve guuid=1210a24f-1800-0000-a3d6-350824120000 pid=4644 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=1210a24f-1800-0000-a3d6-350824120000 pid=4644 execve guuid=2b2eb969-1800-0000-a3d6-350864120000 pid=4708 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=2b2eb969-1800-0000-a3d6-350864120000 pid=4708 execve guuid=c5dbd387-1800-0000-a3d6-3508b7120000 pid=4791 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=c5dbd387-1800-0000-a3d6-3508b7120000 pid=4791 execve guuid=8bdb5c88-1800-0000-a3d6-3508ba120000 pid=4794 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=8bdb5c88-1800-0000-a3d6-3508ba120000 pid=4794 clone guuid=6e5dd388-1800-0000-a3d6-3508bd120000 pid=4797 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=6e5dd388-1800-0000-a3d6-3508bd120000 pid=4797 execve guuid=352c3189-1800-0000-a3d6-3508bf120000 pid=4799 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=352c3189-1800-0000-a3d6-3508bf120000 pid=4799 execve guuid=b4aa8489-1800-0000-a3d6-3508c1120000 pid=4801 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=b4aa8489-1800-0000-a3d6-3508c1120000 pid=4801 execve guuid=aca766a3-1800-0000-a3d6-3508f8120000 pid=4856 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=aca766a3-1800-0000-a3d6-3508f8120000 pid=4856 execve guuid=13a23ec0-1800-0000-a3d6-350833130000 pid=4915 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=13a23ec0-1800-0000-a3d6-350833130000 pid=4915 execve guuid=291dc0c0-1800-0000-a3d6-350836130000 pid=4918 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=291dc0c0-1800-0000-a3d6-350836130000 pid=4918 clone guuid=ec9329c1-1800-0000-a3d6-350838130000 pid=4920 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=ec9329c1-1800-0000-a3d6-350838130000 pid=4920 execve guuid=d84fbbc1-1800-0000-a3d6-35083b130000 pid=4923 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=d84fbbc1-1800-0000-a3d6-35083b130000 pid=4923 execve guuid=775e41c2-1800-0000-a3d6-35083d130000 pid=4925 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=775e41c2-1800-0000-a3d6-35083d130000 pid=4925 execve guuid=e29d9cdc-1800-0000-a3d6-3508a1130000 pid=5025 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=e29d9cdc-1800-0000-a3d6-3508a1130000 pid=5025 execve guuid=674d18f9-1800-0000-a3d6-350807140000 pid=5127 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=674d18f9-1800-0000-a3d6-350807140000 pid=5127 execve guuid=440254f9-1800-0000-a3d6-350809140000 pid=5129 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=440254f9-1800-0000-a3d6-350809140000 pid=5129 clone guuid=595f80f9-1800-0000-a3d6-35080e140000 pid=5134 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=595f80f9-1800-0000-a3d6-35080e140000 pid=5134 execve guuid=769fc3f9-1800-0000-a3d6-35080f140000 pid=5135 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=769fc3f9-1800-0000-a3d6-35080f140000 pid=5135 execve guuid=4d5007fa-1800-0000-a3d6-350811140000 pid=5137 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=4d5007fa-1800-0000-a3d6-350811140000 pid=5137 execve guuid=a36a3815-1900-0000-a3d6-35085d140000 pid=5213 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=a36a3815-1900-0000-a3d6-35085d140000 pid=5213 execve guuid=7cd48931-1900-0000-a3d6-350896140000 pid=5270 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=7cd48931-1900-0000-a3d6-350896140000 pid=5270 execve guuid=6e19de31-1900-0000-a3d6-350897140000 pid=5271 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=6e19de31-1900-0000-a3d6-350897140000 pid=5271 clone guuid=10842c32-1900-0000-a3d6-350899140000 pid=5273 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=10842c32-1900-0000-a3d6-350899140000 pid=5273 execve guuid=ae227a32-1900-0000-a3d6-35089a140000 pid=5274 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=ae227a32-1900-0000-a3d6-35089a140000 pid=5274 execve guuid=6bbdd232-1900-0000-a3d6-35089b140000 pid=5275 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=6bbdd232-1900-0000-a3d6-35089b140000 pid=5275 execve guuid=a736a04d-1900-0000-a3d6-3508a7140000 pid=5287 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=a736a04d-1900-0000-a3d6-3508a7140000 pid=5287 execve guuid=99ce6e69-1900-0000-a3d6-3508a8140000 pid=5288 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=99ce6e69-1900-0000-a3d6-3508a8140000 pid=5288 execve guuid=e4c5c469-1900-0000-a3d6-3508a9140000 pid=5289 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=e4c5c469-1900-0000-a3d6-3508a9140000 pid=5289 clone guuid=4595236a-1900-0000-a3d6-3508ab140000 pid=5291 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=4595236a-1900-0000-a3d6-3508ab140000 pid=5291 execve guuid=6ec36e6a-1900-0000-a3d6-3508ac140000 pid=5292 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=6ec36e6a-1900-0000-a3d6-3508ac140000 pid=5292 execve guuid=db35ba6a-1900-0000-a3d6-3508ad140000 pid=5293 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=db35ba6a-1900-0000-a3d6-3508ad140000 pid=5293 execve guuid=4c6aea84-1900-0000-a3d6-3508ae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=4c6aea84-1900-0000-a3d6-3508ae140000 pid=5294 execve guuid=680b05a0-1900-0000-a3d6-3508af140000 pid=5295 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=680b05a0-1900-0000-a3d6-3508af140000 pid=5295 execve guuid=4b3cd8a0-1900-0000-a3d6-3508b0140000 pid=5296 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=4b3cd8a0-1900-0000-a3d6-3508b0140000 pid=5296 clone guuid=a66e78a1-1900-0000-a3d6-3508b2140000 pid=5298 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=a66e78a1-1900-0000-a3d6-3508b2140000 pid=5298 execve guuid=57dc4aa2-1900-0000-a3d6-3508b3140000 pid=5299 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=57dc4aa2-1900-0000-a3d6-3508b3140000 pid=5299 execve guuid=19a314a3-1900-0000-a3d6-3508b4140000 pid=5300 /usr/bin/wget net send-data guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=19a314a3-1900-0000-a3d6-3508b4140000 pid=5300 execve guuid=00d053be-1900-0000-a3d6-3508b5140000 pid=5301 /usr/bin/curl net send-data write-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=00d053be-1900-0000-a3d6-3508b5140000 pid=5301 execve guuid=5c2995db-1900-0000-a3d6-3508b6140000 pid=5302 /usr/bin/chmod guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=5c2995db-1900-0000-a3d6-3508b6140000 pid=5302 execve guuid=3b1ce3db-1900-0000-a3d6-3508b7140000 pid=5303 /usr/bin/bash guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=3b1ce3db-1900-0000-a3d6-3508b7140000 pid=5303 clone guuid=70ad21dc-1900-0000-a3d6-3508b9140000 pid=5305 /usr/bin/rm delete-file guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=70ad21dc-1900-0000-a3d6-3508b9140000 pid=5305 execve guuid=f53968dc-1900-0000-a3d6-3508ba140000 pid=5306 /usr/bin/rm guuid=88c17730-1700-0000-a3d6-35086a0e0000 pid=3690->guuid=f53968dc-1900-0000-a3d6-3508ba140000 pid=5306 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=8a22c430-1700-0000-a3d6-35086d0e0000 pid=3693->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a765294b-1700-0000-a3d6-3508e00e0000 pid=3808->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=23b09968-1700-0000-a3d6-3508410f0000 pid=3905 /usr/bin/bash guuid=53105568-1700-0000-a3d6-35083f0f0000 pid=3903->guuid=23b09968-1700-0000-a3d6-3508410f0000 pid=3905 clone guuid=92eea969-1700-0000-a3d6-3508450f0000 pid=3909->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=11915584-1700-0000-a3d6-35088b0f0000 pid=3979->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=722c93a2-1700-0000-a3d6-3508f40f0000 pid=4084 /usr/bin/bash guuid=c4ea7da2-1700-0000-a3d6-3508f30f0000 pid=4083->guuid=722c93a2-1700-0000-a3d6-3508f40f0000 pid=4084 clone guuid=e93d2ea3-1700-0000-a3d6-3508f90f0000 pid=4089->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=8c4a54bd-1700-0000-a3d6-350841100000 pid=4161->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=05b42adb-1700-0000-a3d6-3508a4100000 pid=4260 /usr/bin/bash guuid=2d28feda-1700-0000-a3d6-3508a3100000 pid=4259->guuid=05b42adb-1700-0000-a3d6-3508a4100000 pid=4260 clone guuid=e73049dc-1700-0000-a3d6-3508ab100000 pid=4267->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=906c56f7-1700-0000-a3d6-3508ee100000 pid=4334->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=59096f15-1800-0000-a3d6-35084a110000 pid=4426 /usr/bin/bash guuid=6f795015-1800-0000-a3d6-350848110000 pid=4424->guuid=59096f15-1800-0000-a3d6-35084a110000 pid=4426 clone guuid=82322616-1800-0000-a3d6-350850110000 pid=4432->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=8434bd30-1800-0000-a3d6-3508a6110000 pid=4518->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4d12e84e-1800-0000-a3d6-35081f120000 pid=4639 /usr/bin/bash guuid=f219d24e-1800-0000-a3d6-35081e120000 pid=4638->guuid=4d12e84e-1800-0000-a3d6-35081f120000 pid=4639 clone guuid=1210a24f-1800-0000-a3d6-350824120000 pid=4644->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=2b2eb969-1800-0000-a3d6-350864120000 pid=4708->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=86e39388-1800-0000-a3d6-3508bc120000 pid=4796 /usr/bin/bash guuid=8bdb5c88-1800-0000-a3d6-3508ba120000 pid=4794->guuid=86e39388-1800-0000-a3d6-3508bc120000 pid=4796 clone guuid=b4aa8489-1800-0000-a3d6-3508c1120000 pid=4801->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=aca766a3-1800-0000-a3d6-3508f8120000 pid=4856->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4e55e6c0-1800-0000-a3d6-350837130000 pid=4919 /usr/bin/bash guuid=291dc0c0-1800-0000-a3d6-350836130000 pid=4918->guuid=4e55e6c0-1800-0000-a3d6-350837130000 pid=4919 clone guuid=775e41c2-1800-0000-a3d6-35083d130000 pid=4925->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=e29d9cdc-1800-0000-a3d6-3508a1130000 pid=5025->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4d3468f9-1800-0000-a3d6-35080a140000 pid=5130 /usr/bin/bash guuid=440254f9-1800-0000-a3d6-350809140000 pid=5129->guuid=4d3468f9-1800-0000-a3d6-35080a140000 pid=5130 clone guuid=4d5007fa-1800-0000-a3d6-350811140000 pid=5137->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a36a3815-1900-0000-a3d6-35085d140000 pid=5213->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4109ff31-1900-0000-a3d6-350898140000 pid=5272 /usr/bin/bash guuid=6e19de31-1900-0000-a3d6-350897140000 pid=5271->guuid=4109ff31-1900-0000-a3d6-350898140000 pid=5272 clone guuid=6bbdd232-1900-0000-a3d6-35089b140000 pid=5275->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a736a04d-1900-0000-a3d6-3508a7140000 pid=5287->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3d67ea69-1900-0000-a3d6-3508aa140000 pid=5290 /usr/bin/bash guuid=e4c5c469-1900-0000-a3d6-3508a9140000 pid=5289->guuid=3d67ea69-1900-0000-a3d6-3508aa140000 pid=5290 clone guuid=db35ba6a-1900-0000-a3d6-3508ad140000 pid=5293->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4c6aea84-1900-0000-a3d6-3508ae140000 pid=5294->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=c36121a1-1900-0000-a3d6-3508b1140000 pid=5297 /usr/bin/bash guuid=4b3cd8a0-1900-0000-a3d6-3508b0140000 pid=5296->guuid=c36121a1-1900-0000-a3d6-3508b1140000 pid=5297 clone guuid=19a314a3-1900-0000-a3d6-3508b4140000 pid=5300->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=00d053be-1900-0000-a3d6-3508b5140000 pid=5301->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=9e10ffdb-1900-0000-a3d6-3508b8140000 pid=5304 /usr/bin/bash guuid=3b1ce3db-1900-0000-a3d6-3508b7140000 pid=5303->guuid=9e10ffdb-1900-0000-a3d6-3508b8140000 pid=5304 clone
Threat name:
Script.Downloader.Malgent
Status:
Malicious
First seen:
2026-06-11 03:09:38 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 71e947d830bdb4f9aec4b6dbdf36cd04222791defbced6f489800acee3eeed15

(this sample)

  
Delivery method
Distributed via web download

Comments