MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79f997539d2ef2519a8856766e9610b860b6494d1741fdccdbe7f8c1ce93c303. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 79f997539d2ef2519a8856766e9610b860b6494d1741fdccdbe7f8c1ce93c303
SHA3-384 hash: 920a4dabfd77469620c5a946d25288a54989bdead9b02caa9eaf50c3370aaf3561dd62ae5b37439cf32e001c717167b3
SHA1 hash: c34bf5674c9c29af25af11b40b930a032c98306a
MD5 hash: ddccddd1e1c885d49cd84a4c0c29d85b
humanhash: glucose-illinois-quebec-neptune
File name:all.sh
Download: download sample
File size:753 bytes
First seen:2026-01-22 20:35:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:YkF1kcClZF70S9HSHFnHSHF0HSHFWCaFSSEFM5gFWF0HCaFSEEFMDgFWF0zA1LRD:ZDkH/FbJSHFHSHFOSHFWJFBEFM5gFWGn
TLSH T12601DD8531B010F03AEA94D64D335C1C3DC550653D876DFDBC65A4DB59A5F40D062AED
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://172.234.99.70/huhu/titanjr.n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-21T15:21:00Z UTC
Last seen:
2026-01-23T12:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=c6597d1a-1a00-0000-f8a8-601284090000 pid=2436 /usr/bin/sudo guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443 /tmp/sample.bin guuid=c6597d1a-1a00-0000-f8a8-601284090000 pid=2436->guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443 execve guuid=f0b8c31d-1a00-0000-f8a8-60128c090000 pid=2444 /usr/bin/wget net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=f0b8c31d-1a00-0000-f8a8-60128c090000 pid=2444 execve guuid=d8e27724-1a00-0000-f8a8-601299090000 pid=2457 /usr/bin/curl guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=d8e27724-1a00-0000-f8a8-601299090000 pid=2457 execve guuid=1224112c-1a00-0000-f8a8-6012a8090000 pid=2472 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=1224112c-1a00-0000-f8a8-6012a8090000 pid=2472 execve guuid=091bcc2f-1a00-0000-f8a8-6012b2090000 pid=2482 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=091bcc2f-1a00-0000-f8a8-6012b2090000 pid=2482 execve guuid=470e4c3f-1a00-0000-f8a8-6012d8090000 pid=2520 /usr/bin/busybox guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=470e4c3f-1a00-0000-f8a8-6012d8090000 pid=2520 execve guuid=c3dfd03f-1a00-0000-f8a8-6012db090000 pid=2523 /usr/bin/busybox send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=c3dfd03f-1a00-0000-f8a8-6012db090000 pid=2523 execve guuid=e829be42-1d00-0000-f8a8-6012a50f0000 pid=4005 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=e829be42-1d00-0000-f8a8-6012a50f0000 pid=4005 clone guuid=46da1043-1d00-0000-f8a8-6012a70f0000 pid=4007 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=46da1043-1d00-0000-f8a8-6012a70f0000 pid=4007 clone guuid=bd7b3843-1d00-0000-f8a8-6012a80f0000 pid=4008 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=bd7b3843-1d00-0000-f8a8-6012a80f0000 pid=4008 clone guuid=4c8c6743-1d00-0000-f8a8-6012a90f0000 pid=4009 /usr/bin/chmod guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=4c8c6743-1d00-0000-f8a8-6012a90f0000 pid=4009 execve guuid=96beeb43-1d00-0000-f8a8-6012ad0f0000 pid=4013 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=96beeb43-1d00-0000-f8a8-6012ad0f0000 pid=4013 clone guuid=28c6d745-1d00-0000-f8a8-6012b50f0000 pid=4021 /usr/bin/wget net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=28c6d745-1d00-0000-f8a8-6012b50f0000 pid=4021 execve guuid=f8ac204a-1d00-0000-f8a8-6012c20f0000 pid=4034 /usr/bin/curl guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=f8ac204a-1d00-0000-f8a8-6012c20f0000 pid=4034 execve guuid=7dda334e-1d00-0000-f8a8-6012ce0f0000 pid=4046 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=7dda334e-1d00-0000-f8a8-6012ce0f0000 pid=4046 execve guuid=db099151-1d00-0000-f8a8-6012d70f0000 pid=4055 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=db099151-1d00-0000-f8a8-6012d70f0000 pid=4055 execve guuid=fe457760-1d00-0000-f8a8-601208100000 pid=4104 /usr/bin/busybox guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=fe457760-1d00-0000-f8a8-601208100000 pid=4104 execve guuid=1dc43061-1d00-0000-f8a8-60120a100000 pid=4106 /usr/bin/busybox send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=1dc43061-1d00-0000-f8a8-60120a100000 pid=4106 execve guuid=b0294764-2000-0000-f8a8-60127f140000 pid=5247 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=b0294764-2000-0000-f8a8-60127f140000 pid=5247 clone guuid=86689564-2000-0000-f8a8-601280140000 pid=5248 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=86689564-2000-0000-f8a8-601280140000 pid=5248 clone guuid=d3a70565-2000-0000-f8a8-601281140000 pid=5249 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=d3a70565-2000-0000-f8a8-601281140000 pid=5249 clone guuid=6e5b1f65-2000-0000-f8a8-601282140000 pid=5250 /usr/bin/chmod guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=6e5b1f65-2000-0000-f8a8-601282140000 pid=5250 execve guuid=ad138665-2000-0000-f8a8-601283140000 pid=5251 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=ad138665-2000-0000-f8a8-601283140000 pid=5251 clone guuid=1911ab67-2000-0000-f8a8-601285140000 pid=5253 /usr/bin/wget net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=1911ab67-2000-0000-f8a8-601285140000 pid=5253 execve guuid=c399e36c-2000-0000-f8a8-601286140000 pid=5254 /usr/bin/curl guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=c399e36c-2000-0000-f8a8-601286140000 pid=5254 execve guuid=66b4c175-2000-0000-f8a8-601287140000 pid=5255 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=66b4c175-2000-0000-f8a8-601287140000 pid=5255 execve guuid=ee50f779-2000-0000-f8a8-601288140000 pid=5256 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=ee50f779-2000-0000-f8a8-601288140000 pid=5256 execve guuid=52804a8a-2000-0000-f8a8-601289140000 pid=5257 /usr/bin/busybox guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=52804a8a-2000-0000-f8a8-601289140000 pid=5257 execve guuid=b0a9c58b-2000-0000-f8a8-60128a140000 pid=5258 /usr/bin/busybox send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=b0a9c58b-2000-0000-f8a8-60128a140000 pid=5258 execve guuid=40176290-2300-0000-f8a8-6012ab140000 pid=5291 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=40176290-2300-0000-f8a8-6012ab140000 pid=5291 clone guuid=fe999b90-2300-0000-f8a8-6012ac140000 pid=5292 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=fe999b90-2300-0000-f8a8-6012ac140000 pid=5292 clone guuid=3073d990-2300-0000-f8a8-6012ad140000 pid=5293 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=3073d990-2300-0000-f8a8-6012ad140000 pid=5293 clone guuid=42bc0c91-2300-0000-f8a8-6012ae140000 pid=5294 /usr/bin/chmod guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=42bc0c91-2300-0000-f8a8-6012ae140000 pid=5294 execve guuid=1f129391-2300-0000-f8a8-6012af140000 pid=5295 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=1f129391-2300-0000-f8a8-6012af140000 pid=5295 clone guuid=27b5ca92-2300-0000-f8a8-6012b1140000 pid=5297 /usr/bin/wget net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=27b5ca92-2300-0000-f8a8-6012b1140000 pid=5297 execve guuid=c5b71b98-2300-0000-f8a8-6012b2140000 pid=5298 /usr/bin/curl guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=c5b71b98-2300-0000-f8a8-6012b2140000 pid=5298 execve guuid=73e64c9b-2300-0000-f8a8-6012b3140000 pid=5299 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=73e64c9b-2300-0000-f8a8-6012b3140000 pid=5299 execve guuid=dbe1529f-2300-0000-f8a8-6012b4140000 pid=5300 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=dbe1529f-2300-0000-f8a8-6012b4140000 pid=5300 execve guuid=d10dd4af-2300-0000-f8a8-6012b5140000 pid=5301 /usr/bin/busybox guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=d10dd4af-2300-0000-f8a8-6012b5140000 pid=5301 execve guuid=7d80a7b0-2300-0000-f8a8-6012b6140000 pid=5302 /usr/bin/busybox send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=7d80a7b0-2300-0000-f8a8-6012b6140000 pid=5302 execve guuid=ec6a29b4-2600-0000-f8a8-6012b7140000 pid=5303 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=ec6a29b4-2600-0000-f8a8-6012b7140000 pid=5303 clone guuid=5ef646b4-2600-0000-f8a8-6012b8140000 pid=5304 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=5ef646b4-2600-0000-f8a8-6012b8140000 pid=5304 clone guuid=158a8cb4-2600-0000-f8a8-6012b9140000 pid=5305 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=158a8cb4-2600-0000-f8a8-6012b9140000 pid=5305 clone guuid=8fc9a3b4-2600-0000-f8a8-6012ba140000 pid=5306 /usr/bin/chmod guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=8fc9a3b4-2600-0000-f8a8-6012ba140000 pid=5306 execve guuid=f67576b5-2600-0000-f8a8-6012bb140000 pid=5307 /usr/bin/bash guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=f67576b5-2600-0000-f8a8-6012bb140000 pid=5307 clone guuid=67ce0eb6-2600-0000-f8a8-6012bd140000 pid=5309 /usr/bin/wget net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=67ce0eb6-2600-0000-f8a8-6012bd140000 pid=5309 execve guuid=f57812ba-2600-0000-f8a8-6012be140000 pid=5310 /usr/bin/curl guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=f57812ba-2600-0000-f8a8-6012be140000 pid=5310 execve guuid=d21b22bd-2600-0000-f8a8-6012bf140000 pid=5311 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=d21b22bd-2600-0000-f8a8-6012bf140000 pid=5311 execve guuid=bebee6c0-2600-0000-f8a8-6012c0140000 pid=5312 /usr/bin/busybox net send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=bebee6c0-2600-0000-f8a8-6012c0140000 pid=5312 execve guuid=bb381ccf-2600-0000-f8a8-6012c1140000 pid=5313 /usr/bin/busybox guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=bb381ccf-2600-0000-f8a8-6012c1140000 pid=5313 execve guuid=da6fefcf-2600-0000-f8a8-6012c2140000 pid=5314 /usr/bin/busybox send-data guuid=477f6c1d-1a00-0000-f8a8-60128b090000 pid=2443->guuid=da6fefcf-2600-0000-f8a8-6012c2140000 pid=5314 execve f94a013f-dfcc-5d84-8ac7-4d117fdcc605 172.234.99.70:80 guuid=f0b8c31d-1a00-0000-f8a8-60128c090000 pid=2444->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 147B guuid=1224112c-1a00-0000-f8a8-6012a8090000 pid=2472->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 95B 0e1e7ad4-f385-5344-9eb4-2e95f5c46f53 172.234.99.70:21 guuid=091bcc2f-1a00-0000-f8a8-6012b2090000 pid=2482->0e1e7ad4-f385-5344-9eb4-2e95f5c46f53 send: 74B 530c450d-72f9-5661-9b7b-0682e91d40af 172.234.99.70:12713 guuid=091bcc2f-1a00-0000-f8a8-6012b2090000 pid=2482->530c450d-72f9-5661-9b7b-0682e91d40af con 8766b5b3-c553-5710-b7aa-41d46ab0efa9 172.234.99.70:69 guuid=c3dfd03f-1a00-0000-f8a8-6012db090000 pid=2523->8766b5b3-c553-5710-b7aa-41d46ab0efa9 send: 372B guuid=28c6d745-1d00-0000-f8a8-6012b50f0000 pid=4021->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 145B guuid=7dda334e-1d00-0000-f8a8-6012ce0f0000 pid=4046->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 93B guuid=db099151-1d00-0000-f8a8-6012d70f0000 pid=4055->0e1e7ad4-f385-5344-9eb4-2e95f5c46f53 send: 74B 81fdbb59-f7ad-5829-bf34-5cb3d2f7598c 172.234.99.70:63493 guuid=db099151-1d00-0000-f8a8-6012d70f0000 pid=4055->81fdbb59-f7ad-5829-bf34-5cb3d2f7598c con guuid=1dc43061-1d00-0000-f8a8-60120a100000 pid=4106->8766b5b3-c553-5710-b7aa-41d46ab0efa9 send: 348B guuid=1911ab67-2000-0000-f8a8-601285140000 pid=5253->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 145B guuid=66b4c175-2000-0000-f8a8-601287140000 pid=5255->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 93B guuid=ee50f779-2000-0000-f8a8-601288140000 pid=5256->0e1e7ad4-f385-5344-9eb4-2e95f5c46f53 send: 74B b5c3f7f6-6d7c-589d-b034-8c16055250d6 172.234.99.70:41488 guuid=ee50f779-2000-0000-f8a8-601288140000 pid=5256->b5c3f7f6-6d7c-589d-b034-8c16055250d6 con guuid=b0a9c58b-2000-0000-f8a8-60128a140000 pid=5258->8766b5b3-c553-5710-b7aa-41d46ab0efa9 send: 348B guuid=27b5ca92-2300-0000-f8a8-6012b1140000 pid=5297->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 144B guuid=73e64c9b-2300-0000-f8a8-6012b3140000 pid=5299->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 92B guuid=dbe1529f-2300-0000-f8a8-6012b4140000 pid=5300->0e1e7ad4-f385-5344-9eb4-2e95f5c46f53 send: 74B 218cbef7-9e07-50e8-8c2f-d2ae1d685581 172.234.99.70:49821 guuid=dbe1529f-2300-0000-f8a8-6012b4140000 pid=5300->218cbef7-9e07-50e8-8c2f-d2ae1d685581 con guuid=7d80a7b0-2300-0000-f8a8-6012b6140000 pid=5302->8766b5b3-c553-5710-b7aa-41d46ab0efa9 send: 336B guuid=67ce0eb6-2600-0000-f8a8-6012bd140000 pid=5309->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 145B guuid=d21b22bd-2600-0000-f8a8-6012bf140000 pid=5311->f94a013f-dfcc-5d84-8ac7-4d117fdcc605 send: 93B guuid=bebee6c0-2600-0000-f8a8-6012c0140000 pid=5312->0e1e7ad4-f385-5344-9eb4-2e95f5c46f53 send: 74B cb4715d2-27d5-5f40-ba3e-16078ee7b7f7 172.234.99.70:38461 guuid=bebee6c0-2600-0000-f8a8-6012c0140000 pid=5312->cb4715d2-27d5-5f40-ba3e-16078ee7b7f7 con guuid=da6fefcf-2600-0000-f8a8-6012c2140000 pid=5314->8766b5b3-c553-5710-b7aa-41d46ab0efa9 send: 261B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-22 20:36:57 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 79f997539d2ef2519a8856766e9610b860b6494d1741fdccdbe7f8c1ce93c303

(this sample)

  
Delivery method
Distributed via web download

Comments