MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7586c946a3cd97de2c8ba42c3cc7a24f03b04066905d75ade25cfd38fa3b32ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 7586c946a3cd97de2c8ba42c3cc7a24f03b04066905d75ade25cfd38fa3b32ce
SHA3-384 hash: d1691e8f0f9b57595fd01ab21d95f125c55b5baf3fdf46489e57501893b609dc8d78c7f4d9ae35a7e8c03ac49a078131
SHA1 hash: b0ff7bc842e1a0621bc42278281666185536eac3
MD5 hash: 3dea84f07068368cd96824f8e412cf36
humanhash: hawaii-echo-magnesium-fish
File name:ok
Download: download sample
File size:1'644 bytes
First seen:2026-06-17 08:33:00 UTC
Last seen:2026-06-18 08:18:05 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UZ6bgBBsmI6q4rr6tn1w076wTp2Nho76hgNpOGuIHr6IS6p//wbwYi6bwYhGQfFT:4BB3a1pGoO0V5Ki3m65GCfGL2bzH/de
TLSH T17A31708B611419341303DECD73B63948B81E91FB194BE785AD4D0EAD824C6DDF602FD6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/2603c9n/an/aelf ua-wget
http://5.182.210.61/cf835cn/an/aelf ua-wget
http://5.182.210.61/7cccd1n/an/aelf ua-wget
http://5.182.210.61/9b8a04n/an/aelf ua-wget
http://5.182.210.61/45720dn/an/aelf ua-wget
http://5.182.210.61/3db386n/an/aelf ua-wget
http://5.182.210.61/7adcf1n/an/aelf ua-wget
http://5.182.210.61/a41a5an/an/aelf ua-wget
http://5.182.210.61/e7cbc2n/an/aelf ua-wget
http://5.182.210.61/5d4d91n/an/aelf ua-wget
http://5.182.210.61/fee87fn/an/aelf ua-wget
http://5.182.210.61/7382e4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-17T05:38:00Z UTC
Last seen:
2026-06-19T00:55:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=5285bd0c-1700-0000-9176-1e3bc10d0000 pid=3521 /usr/bin/sudo guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526 /tmp/sample.bin guuid=5285bd0c-1700-0000-9176-1e3bc10d0000 pid=3521->guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526 execve guuid=f8370210-1700-0000-9176-1e3bc90d0000 pid=3529 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=f8370210-1700-0000-9176-1e3bc90d0000 pid=3529 execve guuid=4a337913-1700-0000-9176-1e3bd30d0000 pid=3539 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=4a337913-1700-0000-9176-1e3bd30d0000 pid=3539 execve guuid=34dbd118-1700-0000-9176-1e3be30d0000 pid=3555 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=34dbd118-1700-0000-9176-1e3be30d0000 pid=3555 execve guuid=931c2219-1700-0000-9176-1e3be80d0000 pid=3560 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=931c2219-1700-0000-9176-1e3be80d0000 pid=3560 clone guuid=6edd7619-1700-0000-9176-1e3bea0d0000 pid=3562 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=6edd7619-1700-0000-9176-1e3bea0d0000 pid=3562 execve guuid=cda2d019-1700-0000-9176-1e3beb0d0000 pid=3563 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=cda2d019-1700-0000-9176-1e3beb0d0000 pid=3563 execve guuid=61b5251a-1700-0000-9176-1e3bed0d0000 pid=3565 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=61b5251a-1700-0000-9176-1e3bed0d0000 pid=3565 execve guuid=f77b1c1d-1700-0000-9176-1e3bf40d0000 pid=3572 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=f77b1c1d-1700-0000-9176-1e3bf40d0000 pid=3572 execve guuid=cb673b21-1700-0000-9176-1e3b010e0000 pid=3585 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=cb673b21-1700-0000-9176-1e3b010e0000 pid=3585 execve guuid=c1e27521-1700-0000-9176-1e3b030e0000 pid=3587 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=c1e27521-1700-0000-9176-1e3b030e0000 pid=3587 clone guuid=5d4da621-1700-0000-9176-1e3b060e0000 pid=3590 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=5d4da621-1700-0000-9176-1e3b060e0000 pid=3590 execve guuid=39eae221-1700-0000-9176-1e3b070e0000 pid=3591 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=39eae221-1700-0000-9176-1e3b070e0000 pid=3591 execve guuid=19b22422-1700-0000-9176-1e3b090e0000 pid=3593 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=19b22422-1700-0000-9176-1e3b090e0000 pid=3593 execve guuid=f7419424-1700-0000-9176-1e3b120e0000 pid=3602 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=f7419424-1700-0000-9176-1e3b120e0000 pid=3602 execve guuid=1014cd27-1700-0000-9176-1e3b1d0e0000 pid=3613 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=1014cd27-1700-0000-9176-1e3b1d0e0000 pid=3613 execve guuid=98703028-1700-0000-9176-1e3b1f0e0000 pid=3615 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=98703028-1700-0000-9176-1e3b1f0e0000 pid=3615 clone guuid=611f7b28-1700-0000-9176-1e3b210e0000 pid=3617 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=611f7b28-1700-0000-9176-1e3b210e0000 pid=3617 execve guuid=1c6cbb28-1700-0000-9176-1e3b220e0000 pid=3618 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=1c6cbb28-1700-0000-9176-1e3b220e0000 pid=3618 execve guuid=8e911729-1700-0000-9176-1e3b240e0000 pid=3620 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=8e911729-1700-0000-9176-1e3b240e0000 pid=3620 execve guuid=34fc8e2b-1700-0000-9176-1e3b2b0e0000 pid=3627 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=34fc8e2b-1700-0000-9176-1e3b2b0e0000 pid=3627 execve guuid=ac148d2f-1700-0000-9176-1e3b3c0e0000 pid=3644 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=ac148d2f-1700-0000-9176-1e3b3c0e0000 pid=3644 execve guuid=d440ca2f-1700-0000-9176-1e3b3e0e0000 pid=3646 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=d440ca2f-1700-0000-9176-1e3b3e0e0000 pid=3646 clone guuid=085d0630-1700-0000-9176-1e3b420e0000 pid=3650 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=085d0630-1700-0000-9176-1e3b420e0000 pid=3650 execve guuid=59c04a30-1700-0000-9176-1e3b440e0000 pid=3652 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=59c04a30-1700-0000-9176-1e3b440e0000 pid=3652 execve guuid=26368b30-1700-0000-9176-1e3b460e0000 pid=3654 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=26368b30-1700-0000-9176-1e3b460e0000 pid=3654 execve guuid=d93fee32-1700-0000-9176-1e3b500e0000 pid=3664 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=d93fee32-1700-0000-9176-1e3b500e0000 pid=3664 execve guuid=2a8cf235-1700-0000-9176-1e3b5c0e0000 pid=3676 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=2a8cf235-1700-0000-9176-1e3b5c0e0000 pid=3676 execve guuid=0b4f3236-1700-0000-9176-1e3b5d0e0000 pid=3677 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=0b4f3236-1700-0000-9176-1e3b5d0e0000 pid=3677 clone guuid=3c536936-1700-0000-9176-1e3b620e0000 pid=3682 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=3c536936-1700-0000-9176-1e3b620e0000 pid=3682 execve guuid=bb0aac36-1700-0000-9176-1e3b630e0000 pid=3683 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=bb0aac36-1700-0000-9176-1e3b630e0000 pid=3683 execve guuid=792fea36-1700-0000-9176-1e3b670e0000 pid=3687 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=792fea36-1700-0000-9176-1e3b670e0000 pid=3687 execve guuid=d2b98746-1700-0000-9176-1e3b880e0000 pid=3720 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=d2b98746-1700-0000-9176-1e3b880e0000 pid=3720 execve guuid=67ed754c-1700-0000-9176-1e3b950e0000 pid=3733 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=67ed754c-1700-0000-9176-1e3b950e0000 pid=3733 execve guuid=3f96ba4c-1700-0000-9176-1e3b990e0000 pid=3737 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=3f96ba4c-1700-0000-9176-1e3b990e0000 pid=3737 clone guuid=affffa4c-1700-0000-9176-1e3b9b0e0000 pid=3739 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=affffa4c-1700-0000-9176-1e3b9b0e0000 pid=3739 execve guuid=3b57464d-1700-0000-9176-1e3b9c0e0000 pid=3740 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=3b57464d-1700-0000-9176-1e3b9c0e0000 pid=3740 execve guuid=c26a8e4d-1700-0000-9176-1e3b9d0e0000 pid=3741 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=c26a8e4d-1700-0000-9176-1e3b9d0e0000 pid=3741 execve guuid=9a90e550-1700-0000-9176-1e3ba60e0000 pid=3750 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=9a90e550-1700-0000-9176-1e3ba60e0000 pid=3750 execve guuid=1e8bd454-1700-0000-9176-1e3bb60e0000 pid=3766 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=1e8bd454-1700-0000-9176-1e3bb60e0000 pid=3766 execve guuid=6a5f1555-1700-0000-9176-1e3bb80e0000 pid=3768 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=6a5f1555-1700-0000-9176-1e3bb80e0000 pid=3768 clone guuid=45b74855-1700-0000-9176-1e3bbd0e0000 pid=3773 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=45b74855-1700-0000-9176-1e3bbd0e0000 pid=3773 execve guuid=22b08d55-1700-0000-9176-1e3bbe0e0000 pid=3774 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=22b08d55-1700-0000-9176-1e3bbe0e0000 pid=3774 execve guuid=43d5cf55-1700-0000-9176-1e3bc20e0000 pid=3778 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=43d5cf55-1700-0000-9176-1e3bc20e0000 pid=3778 execve guuid=ff9c6259-1700-0000-9176-1e3bce0e0000 pid=3790 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=ff9c6259-1700-0000-9176-1e3bce0e0000 pid=3790 execve guuid=11cbd55e-1700-0000-9176-1e3bde0e0000 pid=3806 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=11cbd55e-1700-0000-9176-1e3bde0e0000 pid=3806 execve guuid=3443175f-1700-0000-9176-1e3bdf0e0000 pid=3807 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=3443175f-1700-0000-9176-1e3bdf0e0000 pid=3807 clone guuid=844e4e5f-1700-0000-9176-1e3be20e0000 pid=3810 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=844e4e5f-1700-0000-9176-1e3be20e0000 pid=3810 execve guuid=b58f925f-1700-0000-9176-1e3be40e0000 pid=3812 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=b58f925f-1700-0000-9176-1e3be40e0000 pid=3812 execve guuid=bc63d35f-1700-0000-9176-1e3be60e0000 pid=3814 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=bc63d35f-1700-0000-9176-1e3be60e0000 pid=3814 execve guuid=7b314d62-1700-0000-9176-1e3bf30e0000 pid=3827 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=7b314d62-1700-0000-9176-1e3bf30e0000 pid=3827 execve guuid=0e81ac65-1700-0000-9176-1e3b070f0000 pid=3847 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=0e81ac65-1700-0000-9176-1e3b070f0000 pid=3847 execve guuid=c429f265-1700-0000-9176-1e3b0a0f0000 pid=3850 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=c429f265-1700-0000-9176-1e3b0a0f0000 pid=3850 clone guuid=897c2666-1700-0000-9176-1e3b0d0f0000 pid=3853 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=897c2666-1700-0000-9176-1e3b0d0f0000 pid=3853 execve guuid=b0e18866-1700-0000-9176-1e3b110f0000 pid=3857 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=b0e18866-1700-0000-9176-1e3b110f0000 pid=3857 execve guuid=3087c366-1700-0000-9176-1e3b130f0000 pid=3859 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=3087c366-1700-0000-9176-1e3b130f0000 pid=3859 execve guuid=dbc32669-1700-0000-9176-1e3b260f0000 pid=3878 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=dbc32669-1700-0000-9176-1e3b260f0000 pid=3878 execve guuid=566fba6d-1700-0000-9176-1e3b360f0000 pid=3894 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=566fba6d-1700-0000-9176-1e3b360f0000 pid=3894 execve guuid=5241f86d-1700-0000-9176-1e3b3a0f0000 pid=3898 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=5241f86d-1700-0000-9176-1e3b3a0f0000 pid=3898 clone guuid=3f92356e-1700-0000-9176-1e3b3c0f0000 pid=3900 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=3f92356e-1700-0000-9176-1e3b3c0f0000 pid=3900 execve guuid=0eeb736e-1700-0000-9176-1e3b3f0f0000 pid=3903 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=0eeb736e-1700-0000-9176-1e3b3f0f0000 pid=3903 execve guuid=37fdbb6e-1700-0000-9176-1e3b410f0000 pid=3905 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=37fdbb6e-1700-0000-9176-1e3b410f0000 pid=3905 execve guuid=09053b71-1700-0000-9176-1e3b4d0f0000 pid=3917 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=09053b71-1700-0000-9176-1e3b4d0f0000 pid=3917 execve guuid=ab6bdf74-1700-0000-9176-1e3b5c0f0000 pid=3932 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=ab6bdf74-1700-0000-9176-1e3b5c0f0000 pid=3932 execve guuid=e22d2975-1700-0000-9176-1e3b600f0000 pid=3936 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=e22d2975-1700-0000-9176-1e3b600f0000 pid=3936 clone guuid=13fc6c75-1700-0000-9176-1e3b620f0000 pid=3938 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=13fc6c75-1700-0000-9176-1e3b620f0000 pid=3938 execve guuid=faa9cd75-1700-0000-9176-1e3b640f0000 pid=3940 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=faa9cd75-1700-0000-9176-1e3b640f0000 pid=3940 execve guuid=b4dc0776-1700-0000-9176-1e3b670f0000 pid=3943 /usr/bin/wget net send-data guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=b4dc0776-1700-0000-9176-1e3b670f0000 pid=3943 execve guuid=a487ba78-1700-0000-9176-1e3b740f0000 pid=3956 /usr/bin/curl net send-data write-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=a487ba78-1700-0000-9176-1e3b740f0000 pid=3956 execve guuid=70b68a7c-1700-0000-9176-1e3b880f0000 pid=3976 /usr/bin/chmod guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=70b68a7c-1700-0000-9176-1e3b880f0000 pid=3976 execve guuid=77cfcc7c-1700-0000-9176-1e3b8a0f0000 pid=3978 /usr/bin/bash guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=77cfcc7c-1700-0000-9176-1e3b8a0f0000 pid=3978 clone guuid=be7e037d-1700-0000-9176-1e3b8d0f0000 pid=3981 /usr/bin/rm delete-file guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=be7e037d-1700-0000-9176-1e3b8d0f0000 pid=3981 execve guuid=818e4e7d-1700-0000-9176-1e3b8e0f0000 pid=3982 /usr/bin/rm guuid=f2ec8a0f-1700-0000-9176-1e3bc60d0000 pid=3526->guuid=818e4e7d-1700-0000-9176-1e3b8e0f0000 pid=3982 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=f8370210-1700-0000-9176-1e3bc90d0000 pid=3529->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=4a337913-1700-0000-9176-1e3bd30d0000 pid=3539->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=3a524119-1700-0000-9176-1e3be90d0000 pid=3561 /usr/bin/bash guuid=931c2219-1700-0000-9176-1e3be80d0000 pid=3560->guuid=3a524119-1700-0000-9176-1e3be90d0000 pid=3561 clone guuid=61b5251a-1700-0000-9176-1e3bed0d0000 pid=3565->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=f77b1c1d-1700-0000-9176-1e3bf40d0000 pid=3572->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=27de8821-1700-0000-9176-1e3b050e0000 pid=3589 /usr/bin/bash guuid=c1e27521-1700-0000-9176-1e3b030e0000 pid=3587->guuid=27de8821-1700-0000-9176-1e3b050e0000 pid=3589 clone guuid=19b22422-1700-0000-9176-1e3b090e0000 pid=3593->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=f7419424-1700-0000-9176-1e3b120e0000 pid=3602->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=5a7f5128-1700-0000-9176-1e3b200e0000 pid=3616 /usr/bin/bash guuid=98703028-1700-0000-9176-1e3b1f0e0000 pid=3615->guuid=5a7f5128-1700-0000-9176-1e3b200e0000 pid=3616 clone guuid=8e911729-1700-0000-9176-1e3b240e0000 pid=3620->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=34fc8e2b-1700-0000-9176-1e3b2b0e0000 pid=3627->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=673be22f-1700-0000-9176-1e3b410e0000 pid=3649 /usr/bin/bash guuid=d440ca2f-1700-0000-9176-1e3b3e0e0000 pid=3646->guuid=673be22f-1700-0000-9176-1e3b410e0000 pid=3649 clone guuid=26368b30-1700-0000-9176-1e3b460e0000 pid=3654->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=d93fee32-1700-0000-9176-1e3b500e0000 pid=3664->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=2f3f4736-1700-0000-9176-1e3b600e0000 pid=3680 /usr/bin/bash guuid=0b4f3236-1700-0000-9176-1e3b5d0e0000 pid=3677->guuid=2f3f4736-1700-0000-9176-1e3b600e0000 pid=3680 clone guuid=792fea36-1700-0000-9176-1e3b670e0000 pid=3687->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=d2b98746-1700-0000-9176-1e3b880e0000 pid=3720->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=5488d14c-1700-0000-9176-1e3b9a0e0000 pid=3738 /usr/bin/bash guuid=3f96ba4c-1700-0000-9176-1e3b990e0000 pid=3737->guuid=5488d14c-1700-0000-9176-1e3b9a0e0000 pid=3738 clone guuid=c26a8e4d-1700-0000-9176-1e3b9d0e0000 pid=3741->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=9a90e550-1700-0000-9176-1e3ba60e0000 pid=3750->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=b42f2c55-1700-0000-9176-1e3bba0e0000 pid=3770 /usr/bin/bash guuid=6a5f1555-1700-0000-9176-1e3bb80e0000 pid=3768->guuid=b42f2c55-1700-0000-9176-1e3bba0e0000 pid=3770 clone guuid=43d5cf55-1700-0000-9176-1e3bc20e0000 pid=3778->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=ff9c6259-1700-0000-9176-1e3bce0e0000 pid=3790->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0c45305f-1700-0000-9176-1e3be10e0000 pid=3809 /usr/bin/bash guuid=3443175f-1700-0000-9176-1e3bdf0e0000 pid=3807->guuid=0c45305f-1700-0000-9176-1e3be10e0000 pid=3809 clone guuid=bc63d35f-1700-0000-9176-1e3be60e0000 pid=3814->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=7b314d62-1700-0000-9176-1e3bf30e0000 pid=3827->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=6bdb0c66-1700-0000-9176-1e3b0c0f0000 pid=3852 /usr/bin/bash guuid=c429f265-1700-0000-9176-1e3b0a0f0000 pid=3850->guuid=6bdb0c66-1700-0000-9176-1e3b0c0f0000 pid=3852 clone guuid=3087c366-1700-0000-9176-1e3b130f0000 pid=3859->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=dbc32669-1700-0000-9176-1e3b260f0000 pid=3878->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=82030d6e-1700-0000-9176-1e3b3b0f0000 pid=3899 /usr/bin/bash guuid=5241f86d-1700-0000-9176-1e3b3a0f0000 pid=3898->guuid=82030d6e-1700-0000-9176-1e3b3b0f0000 pid=3899 clone guuid=37fdbb6e-1700-0000-9176-1e3b410f0000 pid=3905->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=09053b71-1700-0000-9176-1e3b4d0f0000 pid=3917->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0d9f4375-1700-0000-9176-1e3b610f0000 pid=3937 /usr/bin/bash guuid=e22d2975-1700-0000-9176-1e3b600f0000 pid=3936->guuid=0d9f4375-1700-0000-9176-1e3b610f0000 pid=3937 clone guuid=b4dc0776-1700-0000-9176-1e3b670f0000 pid=3943->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=a487ba78-1700-0000-9176-1e3b740f0000 pid=3956->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=dfede37c-1700-0000-9176-1e3b8b0f0000 pid=3979 /usr/bin/bash guuid=77cfcc7c-1700-0000-9176-1e3b8a0f0000 pid=3978->guuid=dfede37c-1700-0000-9176-1e3b8b0f0000 pid=3979 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-17 08:33:26 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7586c946a3cd97de2c8ba42c3cc7a24f03b04066905d75ade25cfd38fa3b32ce

(this sample)

  
Delivery method
Distributed via web download

Comments