MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7fc5f129253acfbf6fc86e072056791ec66cd30c2a5db7013d8eca0d76a5e52c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 7fc5f129253acfbf6fc86e072056791ec66cd30c2a5db7013d8eca0d76a5e52c
SHA3-384 hash: c0b42509873a4543fb6d99f516f17593a0b5188d225a3b1919194853c76153ce6a63af8b5619c3cb315bc30e91e5c422
SHA1 hash: 0a7cbeaf02cb1f93fcda9cdcf16ce33f43fa482b
MD5 hash: 3395c3641bc1f1fc20ac4b7865579357
humanhash: august-three-purple-jupiter
File name:ok
Download: download sample
File size:1'608 bytes
First seen:2026-06-08 17:11:23 UTC
Last seen:2026-06-09 02:42:39 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:59lr9ZHkLrGfWA3Hrr3hAUN3Mtyr9iAa/WprfPG5r/EtBkRkuzHrruzIJptI5rI9:tH7WP2aQwEtBkR5HCIJpMvlO7x
TLSH T19B3136EB4B053A9D4401D9A673651648E0A8E6DA304FE764FF491CBBA3C85483359F4E
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/e14641n/an/aelf ua-wget
http://45.205.1.59/91e87an/an/aelf ua-wget
http://45.205.1.59/2ebaden/an/aelf ua-wget
http://45.205.1.59/2e2e37n/an/aelf ua-wget
http://45.205.1.59/36ff62n/an/aelf ua-wget
http://45.205.1.59/6a41dan/an/aelf ua-wget
http://45.205.1.59/552589n/an/aelf ua-wget
http://45.205.1.59/928fd9n/an/aelf ua-wget
http://45.205.1.59/631474n/an/aelf ua-wget
http://45.205.1.59/2a30e9n/an/aelf ua-wget
http://45.205.1.59/c2bd1dn/an/aelf ua-wget
http://45.205.1.59/5dd7bfn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-08T14:19:00Z UTC
Last seen:
2026-06-08T14:47:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f42235f4-1600-0000-9a51-cece290e0000 pid=3625 /usr/bin/sudo guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631 /tmp/sample.bin guuid=f42235f4-1600-0000-9a51-cece290e0000 pid=3625->guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631 execve guuid=b64cf4f6-1600-0000-9a51-cece330e0000 pid=3635 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=b64cf4f6-1600-0000-9a51-cece330e0000 pid=3635 execve guuid=18a31214-1700-0000-9a51-cece670e0000 pid=3687 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=18a31214-1700-0000-9a51-cece670e0000 pid=3687 execve guuid=4088fd32-1700-0000-9a51-cecef10e0000 pid=3825 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=4088fd32-1700-0000-9a51-cecef10e0000 pid=3825 execve guuid=258d9133-1700-0000-9a51-cecef20e0000 pid=3826 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=258d9133-1700-0000-9a51-cecef20e0000 pid=3826 clone guuid=67fbd233-1700-0000-9a51-cecef40e0000 pid=3828 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=67fbd233-1700-0000-9a51-cecef40e0000 pid=3828 execve guuid=d723d038-1700-0000-9a51-cecef50e0000 pid=3829 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=d723d038-1700-0000-9a51-cecef50e0000 pid=3829 execve guuid=545f0d39-1700-0000-9a51-cecef90e0000 pid=3833 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=545f0d39-1700-0000-9a51-cecef90e0000 pid=3833 execve guuid=0e9de454-1700-0000-9a51-cece4e0f0000 pid=3918 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=0e9de454-1700-0000-9a51-cece4e0f0000 pid=3918 execve guuid=1b86a271-1700-0000-9a51-cecec30f0000 pid=4035 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=1b86a271-1700-0000-9a51-cecec30f0000 pid=4035 execve guuid=826b2472-1700-0000-9a51-cecec40f0000 pid=4036 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=826b2472-1700-0000-9a51-cecec40f0000 pid=4036 clone guuid=52b65a72-1700-0000-9a51-cecec80f0000 pid=4040 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=52b65a72-1700-0000-9a51-cecec80f0000 pid=4040 execve guuid=4766e372-1700-0000-9a51-cececb0f0000 pid=4043 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=4766e372-1700-0000-9a51-cececb0f0000 pid=4043 execve guuid=8e2e6673-1700-0000-9a51-cececd0f0000 pid=4045 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=8e2e6673-1700-0000-9a51-cececd0f0000 pid=4045 execve guuid=ccab758f-1700-0000-9a51-cece41100000 pid=4161 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=ccab758f-1700-0000-9a51-cece41100000 pid=4161 execve guuid=26e6b7ab-1700-0000-9a51-cecebd100000 pid=4285 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=26e6b7ab-1700-0000-9a51-cecebd100000 pid=4285 execve guuid=117c48ac-1700-0000-9a51-cecec0100000 pid=4288 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=117c48ac-1700-0000-9a51-cecec0100000 pid=4288 clone guuid=aab0e3ac-1700-0000-9a51-cecec3100000 pid=4291 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=aab0e3ac-1700-0000-9a51-cecec3100000 pid=4291 execve guuid=6ee142ad-1700-0000-9a51-cecec5100000 pid=4293 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=6ee142ad-1700-0000-9a51-cecec5100000 pid=4293 execve guuid=07ad9bad-1700-0000-9a51-cecec6100000 pid=4294 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=07ad9bad-1700-0000-9a51-cecec6100000 pid=4294 execve guuid=36950ac9-1700-0000-9a51-cece0a110000 pid=4362 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=36950ac9-1700-0000-9a51-cece0a110000 pid=4362 execve guuid=c292b3e7-1700-0000-9a51-cece52110000 pid=4434 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=c292b3e7-1700-0000-9a51-cece52110000 pid=4434 execve guuid=871835e8-1700-0000-9a51-cece54110000 pid=4436 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=871835e8-1700-0000-9a51-cece54110000 pid=4436 clone guuid=1b23b9e8-1700-0000-9a51-cece57110000 pid=4439 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=1b23b9e8-1700-0000-9a51-cece57110000 pid=4439 execve guuid=50f649e9-1700-0000-9a51-cece59110000 pid=4441 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=50f649e9-1700-0000-9a51-cece59110000 pid=4441 execve guuid=101ee5e9-1700-0000-9a51-cece5d110000 pid=4445 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=101ee5e9-1700-0000-9a51-cece5d110000 pid=4445 execve guuid=ad5b2b06-1800-0000-9a51-cecea4110000 pid=4516 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=ad5b2b06-1800-0000-9a51-cecea4110000 pid=4516 execve guuid=637a4823-1800-0000-9a51-cecef1110000 pid=4593 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=637a4823-1800-0000-9a51-cecef1110000 pid=4593 execve guuid=ced3a623-1800-0000-9a51-cecef2110000 pid=4594 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=ced3a623-1800-0000-9a51-cecef2110000 pid=4594 clone guuid=491dee23-1800-0000-9a51-cecef7110000 pid=4599 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=491dee23-1800-0000-9a51-cecef7110000 pid=4599 execve guuid=a3ef3e24-1800-0000-9a51-cecef8110000 pid=4600 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=a3ef3e24-1800-0000-9a51-cecef8110000 pid=4600 execve guuid=bb968d24-1800-0000-9a51-cecefa110000 pid=4602 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=bb968d24-1800-0000-9a51-cecefa110000 pid=4602 execve guuid=54089c41-1800-0000-9a51-cece38120000 pid=4664 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=54089c41-1800-0000-9a51-cece38120000 pid=4664 execve guuid=48f2fc61-1800-0000-9a51-cece8a120000 pid=4746 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=48f2fc61-1800-0000-9a51-cece8a120000 pid=4746 execve guuid=49e88062-1800-0000-9a51-cece8c120000 pid=4748 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=49e88062-1800-0000-9a51-cece8c120000 pid=4748 clone guuid=d767ec62-1800-0000-9a51-cece8f120000 pid=4751 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=d767ec62-1800-0000-9a51-cece8f120000 pid=4751 execve guuid=13517763-1800-0000-9a51-cece91120000 pid=4753 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=13517763-1800-0000-9a51-cece91120000 pid=4753 execve guuid=b0dff763-1800-0000-9a51-cece94120000 pid=4756 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=b0dff763-1800-0000-9a51-cece94120000 pid=4756 execve guuid=d3e07e81-1800-0000-9a51-cececb120000 pid=4811 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=d3e07e81-1800-0000-9a51-cececb120000 pid=4811 execve guuid=f8b4c29e-1800-0000-9a51-cece0c130000 pid=4876 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=f8b4c29e-1800-0000-9a51-cece0c130000 pid=4876 execve guuid=061c449f-1800-0000-9a51-cece0e130000 pid=4878 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=061c449f-1800-0000-9a51-cece0e130000 pid=4878 clone guuid=1953b89f-1800-0000-9a51-cece11130000 pid=4881 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=1953b89f-1800-0000-9a51-cece11130000 pid=4881 execve guuid=3d3239a0-1800-0000-9a51-cece13130000 pid=4883 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3d3239a0-1800-0000-9a51-cece13130000 pid=4883 execve guuid=2e70b7a0-1800-0000-9a51-cece15130000 pid=4885 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=2e70b7a0-1800-0000-9a51-cece15130000 pid=4885 execve guuid=0d96a0bc-1800-0000-9a51-cece4e130000 pid=4942 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=0d96a0bc-1800-0000-9a51-cece4e130000 pid=4942 execve guuid=478a73dc-1800-0000-9a51-ceceb3130000 pid=5043 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=478a73dc-1800-0000-9a51-ceceb3130000 pid=5043 execve guuid=76c7d9dc-1800-0000-9a51-ceceb5130000 pid=5045 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=76c7d9dc-1800-0000-9a51-ceceb5130000 pid=5045 clone guuid=36a397dd-1800-0000-9a51-ceceb8130000 pid=5048 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=36a397dd-1800-0000-9a51-ceceb8130000 pid=5048 execve guuid=9aac4dde-1800-0000-9a51-ceceba130000 pid=5050 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=9aac4dde-1800-0000-9a51-ceceba130000 pid=5050 execve guuid=b672f2de-1800-0000-9a51-cecebc130000 pid=5052 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=b672f2de-1800-0000-9a51-cecebc130000 pid=5052 execve guuid=2800b0fa-1800-0000-9a51-cece17140000 pid=5143 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=2800b0fa-1800-0000-9a51-cece17140000 pid=5143 execve guuid=959f4f18-1900-0000-9a51-cece5b140000 pid=5211 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=959f4f18-1900-0000-9a51-cece5b140000 pid=5211 execve guuid=40c2cd18-1900-0000-9a51-cece5d140000 pid=5213 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=40c2cd18-1900-0000-9a51-cece5d140000 pid=5213 clone guuid=fb184319-1900-0000-9a51-cece60140000 pid=5216 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=fb184319-1900-0000-9a51-cece60140000 pid=5216 execve guuid=3c29bf19-1900-0000-9a51-cece62140000 pid=5218 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3c29bf19-1900-0000-9a51-cece62140000 pid=5218 execve guuid=de43691a-1900-0000-9a51-cece64140000 pid=5220 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=de43691a-1900-0000-9a51-cece64140000 pid=5220 execve guuid=e0abe036-1900-0000-9a51-cece9c140000 pid=5276 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=e0abe036-1900-0000-9a51-cece9c140000 pid=5276 execve guuid=3c89f468-1900-0000-9a51-cecea8140000 pid=5288 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3c89f468-1900-0000-9a51-cecea8140000 pid=5288 execve guuid=1c504f69-1900-0000-9a51-cecea9140000 pid=5289 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=1c504f69-1900-0000-9a51-cecea9140000 pid=5289 clone guuid=b7edb269-1900-0000-9a51-ceceab140000 pid=5291 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=b7edb269-1900-0000-9a51-ceceab140000 pid=5291 execve guuid=7632066a-1900-0000-9a51-ceceac140000 pid=5292 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=7632066a-1900-0000-9a51-ceceac140000 pid=5292 execve guuid=19f4546a-1900-0000-9a51-cecead140000 pid=5293 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=19f4546a-1900-0000-9a51-cecead140000 pid=5293 execve guuid=3dc15d86-1900-0000-9a51-ceceae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3dc15d86-1900-0000-9a51-ceceae140000 pid=5294 execve guuid=e58c7da5-1900-0000-9a51-ceceaf140000 pid=5295 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=e58c7da5-1900-0000-9a51-ceceaf140000 pid=5295 execve guuid=3f11fea5-1900-0000-9a51-ceceb0140000 pid=5296 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3f11fea5-1900-0000-9a51-ceceb0140000 pid=5296 clone guuid=6c644fa6-1900-0000-9a51-ceceb2140000 pid=5298 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=6c644fa6-1900-0000-9a51-ceceb2140000 pid=5298 execve guuid=3e08ada6-1900-0000-9a51-ceceb3140000 pid=5299 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3e08ada6-1900-0000-9a51-ceceb3140000 pid=5299 execve guuid=01bf2da7-1900-0000-9a51-ceceb4140000 pid=5300 /usr/bin/wget net send-data guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=01bf2da7-1900-0000-9a51-ceceb4140000 pid=5300 execve guuid=e3893dc3-1900-0000-9a51-ceceb5140000 pid=5301 /usr/bin/curl net send-data write-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=e3893dc3-1900-0000-9a51-ceceb5140000 pid=5301 execve guuid=570bc8e3-1900-0000-9a51-ceceb6140000 pid=5302 /usr/bin/chmod guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=570bc8e3-1900-0000-9a51-ceceb6140000 pid=5302 execve guuid=704e81e4-1900-0000-9a51-ceceb7140000 pid=5303 /usr/bin/bash guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=704e81e4-1900-0000-9a51-ceceb7140000 pid=5303 clone guuid=3bbdfde4-1900-0000-9a51-ceceb9140000 pid=5305 /usr/bin/rm delete-file guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=3bbdfde4-1900-0000-9a51-ceceb9140000 pid=5305 execve guuid=da62b7e5-1900-0000-9a51-ceceba140000 pid=5306 /usr/bin/rm guuid=b19b8df6-1600-0000-9a51-cece2f0e0000 pid=3631->guuid=da62b7e5-1900-0000-9a51-ceceba140000 pid=5306 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=b64cf4f6-1600-0000-9a51-cece330e0000 pid=3635->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=18a31214-1700-0000-9a51-cece670e0000 pid=3687->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d9e9aa33-1700-0000-9a51-cecef30e0000 pid=3827 /usr/bin/bash guuid=258d9133-1700-0000-9a51-cecef20e0000 pid=3826->guuid=d9e9aa33-1700-0000-9a51-cecef30e0000 pid=3827 clone guuid=545f0d39-1700-0000-9a51-cecef90e0000 pid=3833->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=0e9de454-1700-0000-9a51-cece4e0f0000 pid=3918->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=a0e73d72-1700-0000-9a51-cecec50f0000 pid=4037 /usr/bin/bash guuid=826b2472-1700-0000-9a51-cecec40f0000 pid=4036->guuid=a0e73d72-1700-0000-9a51-cecec50f0000 pid=4037 clone guuid=8e2e6673-1700-0000-9a51-cececd0f0000 pid=4045->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=ccab758f-1700-0000-9a51-cece41100000 pid=4161->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=1510b4ac-1700-0000-9a51-cecec1100000 pid=4289 /usr/bin/bash guuid=117c48ac-1700-0000-9a51-cecec0100000 pid=4288->guuid=1510b4ac-1700-0000-9a51-cecec1100000 pid=4289 clone guuid=07ad9bad-1700-0000-9a51-cecec6100000 pid=4294->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=36950ac9-1700-0000-9a51-cece0a110000 pid=4362->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=6a425fe8-1700-0000-9a51-cece56110000 pid=4438 /usr/bin/bash guuid=871835e8-1700-0000-9a51-cece54110000 pid=4436->guuid=6a425fe8-1700-0000-9a51-cece56110000 pid=4438 clone guuid=101ee5e9-1700-0000-9a51-cece5d110000 pid=4445->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=ad5b2b06-1800-0000-9a51-cecea4110000 pid=4516->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=b2c6c523-1800-0000-9a51-cecef3110000 pid=4595 /usr/bin/bash guuid=ced3a623-1800-0000-9a51-cecef2110000 pid=4594->guuid=b2c6c523-1800-0000-9a51-cecef3110000 pid=4595 clone guuid=bb968d24-1800-0000-9a51-cecefa110000 pid=4602->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=54089c41-1800-0000-9a51-cece38120000 pid=4664->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=2414b262-1800-0000-9a51-cece8d120000 pid=4749 /usr/bin/bash guuid=49e88062-1800-0000-9a51-cece8c120000 pid=4748->guuid=2414b262-1800-0000-9a51-cece8d120000 pid=4749 clone guuid=b0dff763-1800-0000-9a51-cece94120000 pid=4756->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=d3e07e81-1800-0000-9a51-cececb120000 pid=4811->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3ff4759f-1800-0000-9a51-cece0f130000 pid=4879 /usr/bin/bash guuid=061c449f-1800-0000-9a51-cece0e130000 pid=4878->guuid=3ff4759f-1800-0000-9a51-cece0f130000 pid=4879 clone guuid=2e70b7a0-1800-0000-9a51-cece15130000 pid=4885->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=0d96a0bc-1800-0000-9a51-cece4e130000 pid=4942->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d4531cdd-1800-0000-9a51-ceceb7130000 pid=5047 /usr/bin/bash guuid=76c7d9dc-1800-0000-9a51-ceceb5130000 pid=5045->guuid=d4531cdd-1800-0000-9a51-ceceb7130000 pid=5047 clone guuid=b672f2de-1800-0000-9a51-cecebc130000 pid=5052->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=2800b0fa-1800-0000-9a51-cece17140000 pid=5143->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=44d90619-1900-0000-9a51-cece5e140000 pid=5214 /usr/bin/bash guuid=40c2cd18-1900-0000-9a51-cece5d140000 pid=5213->guuid=44d90619-1900-0000-9a51-cece5e140000 pid=5214 clone guuid=de43691a-1900-0000-9a51-cece64140000 pid=5220->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=e0abe036-1900-0000-9a51-cece9c140000 pid=5276->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=e68e6f69-1900-0000-9a51-ceceaa140000 pid=5290 /usr/bin/bash guuid=1c504f69-1900-0000-9a51-cecea9140000 pid=5289->guuid=e68e6f69-1900-0000-9a51-ceceaa140000 pid=5290 clone guuid=19f4546a-1900-0000-9a51-cecead140000 pid=5293->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=3dc15d86-1900-0000-9a51-ceceae140000 pid=5294->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=a61226a6-1900-0000-9a51-ceceb1140000 pid=5297 /usr/bin/bash guuid=3f11fea5-1900-0000-9a51-ceceb0140000 pid=5296->guuid=a61226a6-1900-0000-9a51-ceceb1140000 pid=5297 clone guuid=01bf2da7-1900-0000-9a51-ceceb4140000 pid=5300->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=e3893dc3-1900-0000-9a51-ceceb5140000 pid=5301->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=28afbfe4-1900-0000-9a51-ceceb8140000 pid=5304 /usr/bin/bash guuid=704e81e4-1900-0000-9a51-ceceb7140000 pid=5303->guuid=28afbfe4-1900-0000-9a51-ceceb8140000 pid=5304 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Downloader.Malgent
Status:
Malicious
First seen:
2026-06-08 17:11:57 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7fc5f129253acfbf6fc86e072056791ec66cd30c2a5db7013d8eca0d76a5e52c

(this sample)

  
Delivery method
Distributed via web download

Comments