MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81c6b50efe5c39ba960e8d85ce96ed421b4e31c4e0901ad7d295570ac941f5c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 81c6b50efe5c39ba960e8d85ce96ed421b4e31c4e0901ad7d295570ac941f5c4
SHA3-384 hash: 17046d8e43bbc5acec9a17dba309c79f4da9b7537905471cbaaba4e5e8a0a0adca7367c01d761f2365fb52a0ace984a3
SHA1 hash: 01e0521ab67c9ccfe1fa05f843c0c8036408d786
MD5 hash: 1865fee9530043da7871f7c02fc42d3b
humanhash: texas-island-butter-oklahoma
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-23 03:37:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UR6zBPQ6P371Us6aPw0er6l564wpdZ6pdwPVT6G6baAOvlK6Rqe6udjCKC6PKDjM:FX3NqQ564kNTFy/psG2FX
TLSH T1BB310FDF45112B392602CACE7367255CB40C91EB2D6BC7E8CC8C4EE987A89CC7221B95
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/b83c61n/an/aelf ua-wget
http://5.182.210.61/3a9685n/an/aelf ua-wget
http://5.182.210.61/ff6b53n/an/aelf ua-wget
http://5.182.210.61/0d92bcn/an/aelf ua-wget
http://5.182.210.61/028f6an/an/aelf ua-wget
http://5.182.210.61/3127f9n/an/aelf ua-wget
http://5.182.210.61/1821a1n/an/aelf ua-wget
http://5.182.210.61/15ce08n/an/aelf ua-wget
http://5.182.210.61/53718bn/an/aelf ua-wget
http://5.182.210.61/cac388n/an/aelf ua-wget
http://5.182.210.61/4e4048n/an/aelf ua-wget
http://5.182.210.61/7634e8n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=afac6d6a-1900-0000-dc0d-5f6333140000 pid=5171 /usr/bin/sudo guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172 /tmp/sample.bin guuid=afac6d6a-1900-0000-dc0d-5f6333140000 pid=5171->guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172 execve guuid=3676286f-1900-0000-dc0d-5f6335140000 pid=5173 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=3676286f-1900-0000-dc0d-5f6335140000 pid=5173 execve guuid=52227876-1900-0000-dc0d-5f6336140000 pid=5174 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=52227876-1900-0000-dc0d-5f6336140000 pid=5174 execve guuid=0fbf2386-1900-0000-dc0d-5f6337140000 pid=5175 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=0fbf2386-1900-0000-dc0d-5f6337140000 pid=5175 execve guuid=bb60b98e-1900-0000-dc0d-5f6338140000 pid=5176 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=bb60b98e-1900-0000-dc0d-5f6338140000 pid=5176 clone guuid=f58f3990-1900-0000-dc0d-5f633a140000 pid=5178 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=f58f3990-1900-0000-dc0d-5f633a140000 pid=5178 execve guuid=4eca3694-1900-0000-dc0d-5f633b140000 pid=5179 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=4eca3694-1900-0000-dc0d-5f633b140000 pid=5179 execve guuid=fb78f094-1900-0000-dc0d-5f633c140000 pid=5180 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=fb78f094-1900-0000-dc0d-5f633c140000 pid=5180 execve guuid=50517299-1900-0000-dc0d-5f633d140000 pid=5181 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=50517299-1900-0000-dc0d-5f633d140000 pid=5181 execve guuid=8e11739e-1900-0000-dc0d-5f633e140000 pid=5182 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=8e11739e-1900-0000-dc0d-5f633e140000 pid=5182 execve guuid=06cae89e-1900-0000-dc0d-5f633f140000 pid=5183 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=06cae89e-1900-0000-dc0d-5f633f140000 pid=5183 clone guuid=0ecfee9f-1900-0000-dc0d-5f6341140000 pid=5185 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=0ecfee9f-1900-0000-dc0d-5f6341140000 pid=5185 execve guuid=629a97a0-1900-0000-dc0d-5f6342140000 pid=5186 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=629a97a0-1900-0000-dc0d-5f6342140000 pid=5186 execve guuid=a29b12a1-1900-0000-dc0d-5f6343140000 pid=5187 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=a29b12a1-1900-0000-dc0d-5f6343140000 pid=5187 execve guuid=194391a6-1900-0000-dc0d-5f6344140000 pid=5188 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=194391a6-1900-0000-dc0d-5f6344140000 pid=5188 execve guuid=f1b185af-1900-0000-dc0d-5f6345140000 pid=5189 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=f1b185af-1900-0000-dc0d-5f6345140000 pid=5189 execve guuid=8883c9af-1900-0000-dc0d-5f6346140000 pid=5190 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=8883c9af-1900-0000-dc0d-5f6346140000 pid=5190 clone guuid=eaef05b0-1900-0000-dc0d-5f6348140000 pid=5192 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=eaef05b0-1900-0000-dc0d-5f6348140000 pid=5192 execve guuid=147f50b0-1900-0000-dc0d-5f6349140000 pid=5193 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=147f50b0-1900-0000-dc0d-5f6349140000 pid=5193 execve guuid=cb9c9bb0-1900-0000-dc0d-5f634a140000 pid=5194 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=cb9c9bb0-1900-0000-dc0d-5f634a140000 pid=5194 execve guuid=36e4dcb4-1900-0000-dc0d-5f634b140000 pid=5195 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=36e4dcb4-1900-0000-dc0d-5f634b140000 pid=5195 execve guuid=617fbdbb-1900-0000-dc0d-5f634c140000 pid=5196 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=617fbdbb-1900-0000-dc0d-5f634c140000 pid=5196 execve guuid=d38a11bf-1900-0000-dc0d-5f634d140000 pid=5197 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=d38a11bf-1900-0000-dc0d-5f634d140000 pid=5197 clone guuid=80c985c0-1900-0000-dc0d-5f634f140000 pid=5199 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=80c985c0-1900-0000-dc0d-5f634f140000 pid=5199 execve guuid=a6cce8c0-1900-0000-dc0d-5f6350140000 pid=5200 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=a6cce8c0-1900-0000-dc0d-5f6350140000 pid=5200 execve guuid=086a55c1-1900-0000-dc0d-5f6351140000 pid=5201 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=086a55c1-1900-0000-dc0d-5f6351140000 pid=5201 execve guuid=a51137c4-1900-0000-dc0d-5f6352140000 pid=5202 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=a51137c4-1900-0000-dc0d-5f6352140000 pid=5202 execve guuid=c826fac9-1900-0000-dc0d-5f6353140000 pid=5203 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=c826fac9-1900-0000-dc0d-5f6353140000 pid=5203 execve guuid=4c5d60ca-1900-0000-dc0d-5f6354140000 pid=5204 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=4c5d60ca-1900-0000-dc0d-5f6354140000 pid=5204 clone guuid=e09ccbca-1900-0000-dc0d-5f6356140000 pid=5206 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=e09ccbca-1900-0000-dc0d-5f6356140000 pid=5206 execve guuid=257a18cb-1900-0000-dc0d-5f6357140000 pid=5207 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=257a18cb-1900-0000-dc0d-5f6357140000 pid=5207 execve guuid=2d645ecb-1900-0000-dc0d-5f6358140000 pid=5208 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=2d645ecb-1900-0000-dc0d-5f6358140000 pid=5208 execve guuid=52898fce-1900-0000-dc0d-5f6359140000 pid=5209 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=52898fce-1900-0000-dc0d-5f6359140000 pid=5209 execve guuid=a9bbffd2-1900-0000-dc0d-5f635a140000 pid=5210 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=a9bbffd2-1900-0000-dc0d-5f635a140000 pid=5210 execve guuid=b53764d3-1900-0000-dc0d-5f635b140000 pid=5211 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=b53764d3-1900-0000-dc0d-5f635b140000 pid=5211 clone guuid=b820b5d3-1900-0000-dc0d-5f635d140000 pid=5213 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=b820b5d3-1900-0000-dc0d-5f635d140000 pid=5213 execve guuid=b6d312d4-1900-0000-dc0d-5f635e140000 pid=5214 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=b6d312d4-1900-0000-dc0d-5f635e140000 pid=5214 execve guuid=712967d4-1900-0000-dc0d-5f635f140000 pid=5215 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=712967d4-1900-0000-dc0d-5f635f140000 pid=5215 execve guuid=15262fd7-1900-0000-dc0d-5f6360140000 pid=5216 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=15262fd7-1900-0000-dc0d-5f6360140000 pid=5216 execve guuid=884ccfda-1900-0000-dc0d-5f6361140000 pid=5217 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=884ccfda-1900-0000-dc0d-5f6361140000 pid=5217 execve guuid=210717db-1900-0000-dc0d-5f6362140000 pid=5218 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=210717db-1900-0000-dc0d-5f6362140000 pid=5218 clone guuid=f64162db-1900-0000-dc0d-5f6364140000 pid=5220 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=f64162db-1900-0000-dc0d-5f6364140000 pid=5220 execve guuid=97a4a6db-1900-0000-dc0d-5f6365140000 pid=5221 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=97a4a6db-1900-0000-dc0d-5f6365140000 pid=5221 execve guuid=420ae5db-1900-0000-dc0d-5f6366140000 pid=5222 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=420ae5db-1900-0000-dc0d-5f6366140000 pid=5222 execve guuid=bfa68ade-1900-0000-dc0d-5f6367140000 pid=5223 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=bfa68ade-1900-0000-dc0d-5f6367140000 pid=5223 execve guuid=0e6273e2-1900-0000-dc0d-5f6368140000 pid=5224 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=0e6273e2-1900-0000-dc0d-5f6368140000 pid=5224 execve guuid=f16907e3-1900-0000-dc0d-5f6369140000 pid=5225 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=f16907e3-1900-0000-dc0d-5f6369140000 pid=5225 clone guuid=cd4c86e3-1900-0000-dc0d-5f636b140000 pid=5227 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=cd4c86e3-1900-0000-dc0d-5f636b140000 pid=5227 execve guuid=d703dee3-1900-0000-dc0d-5f636c140000 pid=5228 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=d703dee3-1900-0000-dc0d-5f636c140000 pid=5228 execve guuid=de122fe4-1900-0000-dc0d-5f636d140000 pid=5229 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=de122fe4-1900-0000-dc0d-5f636d140000 pid=5229 execve guuid=777d05e7-1900-0000-dc0d-5f636e140000 pid=5230 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=777d05e7-1900-0000-dc0d-5f636e140000 pid=5230 execve guuid=c0a675eb-1900-0000-dc0d-5f636f140000 pid=5231 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=c0a675eb-1900-0000-dc0d-5f636f140000 pid=5231 execve guuid=6f86caeb-1900-0000-dc0d-5f6370140000 pid=5232 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=6f86caeb-1900-0000-dc0d-5f6370140000 pid=5232 clone guuid=910f20ec-1900-0000-dc0d-5f6372140000 pid=5234 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=910f20ec-1900-0000-dc0d-5f6372140000 pid=5234 execve guuid=d2ca6bec-1900-0000-dc0d-5f6373140000 pid=5235 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=d2ca6bec-1900-0000-dc0d-5f6373140000 pid=5235 execve guuid=e61bb3ec-1900-0000-dc0d-5f6374140000 pid=5236 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=e61bb3ec-1900-0000-dc0d-5f6374140000 pid=5236 execve guuid=819d59ef-1900-0000-dc0d-5f6375140000 pid=5237 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=819d59ef-1900-0000-dc0d-5f6375140000 pid=5237 execve guuid=6cb6cef2-1900-0000-dc0d-5f6376140000 pid=5238 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=6cb6cef2-1900-0000-dc0d-5f6376140000 pid=5238 execve guuid=310e36f3-1900-0000-dc0d-5f6377140000 pid=5239 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=310e36f3-1900-0000-dc0d-5f6377140000 pid=5239 clone guuid=d67190f3-1900-0000-dc0d-5f6379140000 pid=5241 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=d67190f3-1900-0000-dc0d-5f6379140000 pid=5241 execve guuid=db4af5f3-1900-0000-dc0d-5f637a140000 pid=5242 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=db4af5f3-1900-0000-dc0d-5f637a140000 pid=5242 execve guuid=17595bf4-1900-0000-dc0d-5f637b140000 pid=5243 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=17595bf4-1900-0000-dc0d-5f637b140000 pid=5243 execve guuid=085c33f7-1900-0000-dc0d-5f637c140000 pid=5244 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=085c33f7-1900-0000-dc0d-5f637c140000 pid=5244 execve guuid=39904dfd-1900-0000-dc0d-5f637d140000 pid=5245 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=39904dfd-1900-0000-dc0d-5f637d140000 pid=5245 execve guuid=e340b3fd-1900-0000-dc0d-5f637e140000 pid=5246 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=e340b3fd-1900-0000-dc0d-5f637e140000 pid=5246 clone guuid=d91626fe-1900-0000-dc0d-5f6380140000 pid=5248 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=d91626fe-1900-0000-dc0d-5f6380140000 pid=5248 execve guuid=ad3e9ffe-1900-0000-dc0d-5f6381140000 pid=5249 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=ad3e9ffe-1900-0000-dc0d-5f6381140000 pid=5249 execve guuid=d4c01cff-1900-0000-dc0d-5f6382140000 pid=5250 /usr/bin/wget net send-data guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=d4c01cff-1900-0000-dc0d-5f6382140000 pid=5250 execve guuid=1a59e701-1a00-0000-dc0d-5f6383140000 pid=5251 /usr/bin/curl net send-data write-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=1a59e701-1a00-0000-dc0d-5f6383140000 pid=5251 execve guuid=4b602b05-1a00-0000-dc0d-5f6385140000 pid=5253 /usr/bin/chmod guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=4b602b05-1a00-0000-dc0d-5f6385140000 pid=5253 execve guuid=e5597105-1a00-0000-dc0d-5f6386140000 pid=5254 /usr/bin/bash guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=e5597105-1a00-0000-dc0d-5f6386140000 pid=5254 clone guuid=21f4a305-1a00-0000-dc0d-5f6388140000 pid=5256 /usr/bin/rm delete-file guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=21f4a305-1a00-0000-dc0d-5f6388140000 pid=5256 execve guuid=54b9eb05-1a00-0000-dc0d-5f6389140000 pid=5257 /usr/bin/rm guuid=00e7e26d-1900-0000-dc0d-5f6334140000 pid=5172->guuid=54b9eb05-1a00-0000-dc0d-5f6389140000 pid=5257 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=3676286f-1900-0000-dc0d-5f6335140000 pid=5173->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=52227876-1900-0000-dc0d-5f6336140000 pid=5174->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=434f2b8f-1900-0000-dc0d-5f6339140000 pid=5177 /usr/bin/bash guuid=bb60b98e-1900-0000-dc0d-5f6338140000 pid=5176->guuid=434f2b8f-1900-0000-dc0d-5f6339140000 pid=5177 clone guuid=fb78f094-1900-0000-dc0d-5f633c140000 pid=5180->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=50517299-1900-0000-dc0d-5f633d140000 pid=5181->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c5c3389f-1900-0000-dc0d-5f6340140000 pid=5184 /usr/bin/bash guuid=06cae89e-1900-0000-dc0d-5f633f140000 pid=5183->guuid=c5c3389f-1900-0000-dc0d-5f6340140000 pid=5184 clone guuid=a29b12a1-1900-0000-dc0d-5f6343140000 pid=5187->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=194391a6-1900-0000-dc0d-5f6344140000 pid=5188->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=62ede2af-1900-0000-dc0d-5f6347140000 pid=5191 /usr/bin/bash guuid=8883c9af-1900-0000-dc0d-5f6346140000 pid=5190->guuid=62ede2af-1900-0000-dc0d-5f6347140000 pid=5191 clone guuid=cb9c9bb0-1900-0000-dc0d-5f634a140000 pid=5194->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=36e4dcb4-1900-0000-dc0d-5f634b140000 pid=5195->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c39202c0-1900-0000-dc0d-5f634e140000 pid=5198 /usr/bin/bash guuid=d38a11bf-1900-0000-dc0d-5f634d140000 pid=5197->guuid=c39202c0-1900-0000-dc0d-5f634e140000 pid=5198 clone guuid=086a55c1-1900-0000-dc0d-5f6351140000 pid=5201->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=a51137c4-1900-0000-dc0d-5f6352140000 pid=5202->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=412a77ca-1900-0000-dc0d-5f6355140000 pid=5205 /usr/bin/bash guuid=4c5d60ca-1900-0000-dc0d-5f6354140000 pid=5204->guuid=412a77ca-1900-0000-dc0d-5f6355140000 pid=5205 clone guuid=2d645ecb-1900-0000-dc0d-5f6358140000 pid=5208->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=52898fce-1900-0000-dc0d-5f6359140000 pid=5209->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=79ab83d3-1900-0000-dc0d-5f635c140000 pid=5212 /usr/bin/bash guuid=b53764d3-1900-0000-dc0d-5f635b140000 pid=5211->guuid=79ab83d3-1900-0000-dc0d-5f635c140000 pid=5212 clone guuid=712967d4-1900-0000-dc0d-5f635f140000 pid=5215->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=15262fd7-1900-0000-dc0d-5f6360140000 pid=5216->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=068133db-1900-0000-dc0d-5f6363140000 pid=5219 /usr/bin/bash guuid=210717db-1900-0000-dc0d-5f6362140000 pid=5218->guuid=068133db-1900-0000-dc0d-5f6363140000 pid=5219 clone guuid=420ae5db-1900-0000-dc0d-5f6366140000 pid=5222->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=bfa68ade-1900-0000-dc0d-5f6367140000 pid=5223->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=b94f58e3-1900-0000-dc0d-5f636a140000 pid=5226 /usr/bin/bash guuid=f16907e3-1900-0000-dc0d-5f6369140000 pid=5225->guuid=b94f58e3-1900-0000-dc0d-5f636a140000 pid=5226 clone guuid=de122fe4-1900-0000-dc0d-5f636d140000 pid=5229->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=777d05e7-1900-0000-dc0d-5f636e140000 pid=5230->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=1611e5eb-1900-0000-dc0d-5f6371140000 pid=5233 /usr/bin/bash guuid=6f86caeb-1900-0000-dc0d-5f6370140000 pid=5232->guuid=1611e5eb-1900-0000-dc0d-5f6371140000 pid=5233 clone guuid=e61bb3ec-1900-0000-dc0d-5f6374140000 pid=5236->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=819d59ef-1900-0000-dc0d-5f6375140000 pid=5237->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=af3a5ff3-1900-0000-dc0d-5f6378140000 pid=5240 /usr/bin/bash guuid=310e36f3-1900-0000-dc0d-5f6377140000 pid=5239->guuid=af3a5ff3-1900-0000-dc0d-5f6378140000 pid=5240 clone guuid=17595bf4-1900-0000-dc0d-5f637b140000 pid=5243->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=085c33f7-1900-0000-dc0d-5f637c140000 pid=5244->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=8958d6fd-1900-0000-dc0d-5f637f140000 pid=5247 /usr/bin/bash guuid=e340b3fd-1900-0000-dc0d-5f637e140000 pid=5246->guuid=8958d6fd-1900-0000-dc0d-5f637f140000 pid=5247 clone guuid=d4c01cff-1900-0000-dc0d-5f6382140000 pid=5250->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=1a59e701-1a00-0000-dc0d-5f6383140000 pid=5251->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=282b8605-1a00-0000-dc0d-5f6387140000 pid=5255 /usr/bin/bash guuid=e5597105-1a00-0000-dc0d-5f6386140000 pid=5254->guuid=282b8605-1a00-0000-dc0d-5f6387140000 pid=5255 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-06-23 03:38:33 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 81c6b50efe5c39ba960e8d85ce96ed421b4e31c4e0901ad7d295570ac941f5c4

(this sample)

  
Delivery method
Distributed via web download

Comments