MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 829ffb02a7508158f96c2ea5a5690ed058313eddac02cee2874500a9acc67faa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 829ffb02a7508158f96c2ea5a5690ed058313eddac02cee2874500a9acc67faa
SHA3-384 hash: 032b606a69a4e26023477737d2185a704981009f9f000ae83514a724f1848cd91a2d9832104825004485bd572fa00157
SHA1 hash: ada7ee0d9f84157101e3281ffe68c62db254f090
MD5 hash: 167a328aa83651c4e2ade99c02ea520c
humanhash: skylark-aspen-arizona-steak
File name:ok
Download: download sample
File size:1'620 bytes
First seen:2026-06-11 08:58:23 UTC
Last seen:2026-06-11 23:58:02 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:b34GFvNtF8v6rErkQIgSfdMOB7lWCEGEcHwqd8RJ:b34UNtHOk0GdMRSwqGRJ
TLSH T1FC31EAAB1B19396D0904CDBAB3752148E514E2CB108FE7E1FE4E087D92CB549324BE4B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/0846e8n/an/aelf ua-wge
http://45.205.1.59/906033n/an/aelf ua-wge
http://45.205.1.59/70cc1cn/an/aelf ua-wge
http://45.205.1.59/861c97n/an/aelf ua-wge
http://45.205.1.59/f1cc53n/an/aelf ua-wge
http://45.205.1.59/f0e44bn/an/aelf ua-wge
http://45.205.1.59/54660bn/an/aelf ua-wge
http://45.205.1.59/7e8a8cn/an/aelf ua-wge
http://45.205.1.59/8715c3n/an/aelf ua-wge
http://45.205.1.59/e59d20n/an/aelf ua-wge
http://45.205.1.59/b0e1c3n/an/aelf ua-wge
http://45.205.1.59/4ab9a6n/an/aelf ua-wge

Intelligence


File Origin
# of uploads :
3
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=496dbd20-1a00-0000-d11c-b3138a0c0000 pid=3210 /usr/bin/sudo guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216 /tmp/sample.bin guuid=496dbd20-1a00-0000-d11c-b3138a0c0000 pid=3210->guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216 execve guuid=8371c923-1a00-0000-d11c-b313920c0000 pid=3218 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=8371c923-1a00-0000-d11c-b313920c0000 pid=3218 execve guuid=b316e53e-1a00-0000-d11c-b313b00c0000 pid=3248 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=b316e53e-1a00-0000-d11c-b313b00c0000 pid=3248 execve guuid=4cbec35c-1a00-0000-d11c-b313ea0c0000 pid=3306 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=4cbec35c-1a00-0000-d11c-b313ea0c0000 pid=3306 execve guuid=e4882f5d-1a00-0000-d11c-b313ec0c0000 pid=3308 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=e4882f5d-1a00-0000-d11c-b313ec0c0000 pid=3308 clone guuid=58a6915d-1a00-0000-d11c-b313ef0c0000 pid=3311 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=58a6915d-1a00-0000-d11c-b313ef0c0000 pid=3311 execve guuid=8811fc5d-1a00-0000-d11c-b313f10c0000 pid=3313 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=8811fc5d-1a00-0000-d11c-b313f10c0000 pid=3313 execve guuid=c5bb545e-1a00-0000-d11c-b313f30c0000 pid=3315 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=c5bb545e-1a00-0000-d11c-b313f30c0000 pid=3315 execve guuid=955e2779-1a00-0000-d11c-b313130d0000 pid=3347 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=955e2779-1a00-0000-d11c-b313130d0000 pid=3347 execve guuid=8e044596-1a00-0000-d11c-b313290d0000 pid=3369 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=8e044596-1a00-0000-d11c-b313290d0000 pid=3369 execve guuid=b0820797-1a00-0000-d11c-b3132a0d0000 pid=3370 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=b0820797-1a00-0000-d11c-b3132a0d0000 pid=3370 clone guuid=eef77497-1a00-0000-d11c-b3132c0d0000 pid=3372 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=eef77497-1a00-0000-d11c-b3132c0d0000 pid=3372 execve guuid=7f51f897-1a00-0000-d11c-b3132d0d0000 pid=3373 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=7f51f897-1a00-0000-d11c-b3132d0d0000 pid=3373 execve guuid=23966c98-1a00-0000-d11c-b3132e0d0000 pid=3374 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=23966c98-1a00-0000-d11c-b3132e0d0000 pid=3374 execve guuid=6669f9b1-1a00-0000-d11c-b313510d0000 pid=3409 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=6669f9b1-1a00-0000-d11c-b313510d0000 pid=3409 execve guuid=8745a2cd-1a00-0000-d11c-b3139d0d0000 pid=3485 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=8745a2cd-1a00-0000-d11c-b3139d0d0000 pid=3485 execve guuid=37f2e5cd-1a00-0000-d11c-b3139f0d0000 pid=3487 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=37f2e5cd-1a00-0000-d11c-b3139f0d0000 pid=3487 clone guuid=d13120ce-1a00-0000-d11c-b313a20d0000 pid=3490 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=d13120ce-1a00-0000-d11c-b313a20d0000 pid=3490 execve guuid=fb496bce-1a00-0000-d11c-b313a30d0000 pid=3491 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=fb496bce-1a00-0000-d11c-b313a30d0000 pid=3491 execve guuid=a7a1acce-1a00-0000-d11c-b313a50d0000 pid=3493 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=a7a1acce-1a00-0000-d11c-b313a50d0000 pid=3493 execve guuid=ac11e4e7-1a00-0000-d11c-b313d20d0000 pid=3538 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=ac11e4e7-1a00-0000-d11c-b313d20d0000 pid=3538 execve guuid=6aeb2307-1b00-0000-d11c-b313110e0000 pid=3601 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=6aeb2307-1b00-0000-d11c-b313110e0000 pid=3601 execve guuid=be756f07-1b00-0000-d11c-b313130e0000 pid=3603 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=be756f07-1b00-0000-d11c-b313130e0000 pid=3603 clone guuid=a95fcd07-1b00-0000-d11c-b313160e0000 pid=3606 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=a95fcd07-1b00-0000-d11c-b313160e0000 pid=3606 execve guuid=7b943808-1b00-0000-d11c-b313180e0000 pid=3608 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=7b943808-1b00-0000-d11c-b313180e0000 pid=3608 execve guuid=02d39908-1b00-0000-d11c-b3131a0e0000 pid=3610 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=02d39908-1b00-0000-d11c-b3131a0e0000 pid=3610 execve guuid=f0bc8f22-1b00-0000-d11c-b313590e0000 pid=3673 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=f0bc8f22-1b00-0000-d11c-b313590e0000 pid=3673 execve guuid=9693293e-1b00-0000-d11c-b313740e0000 pid=3700 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=9693293e-1b00-0000-d11c-b313740e0000 pid=3700 execve guuid=39358f3e-1b00-0000-d11c-b313780e0000 pid=3704 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=39358f3e-1b00-0000-d11c-b313780e0000 pid=3704 clone guuid=0002cf3e-1b00-0000-d11c-b3137a0e0000 pid=3706 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=0002cf3e-1b00-0000-d11c-b3137a0e0000 pid=3706 execve guuid=4a711d3f-1b00-0000-d11c-b3137b0e0000 pid=3707 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=4a711d3f-1b00-0000-d11c-b3137b0e0000 pid=3707 execve guuid=bfbb713f-1b00-0000-d11c-b3137c0e0000 pid=3708 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=bfbb713f-1b00-0000-d11c-b3137c0e0000 pid=3708 execve guuid=4389b759-1b00-0000-d11c-b313de0e0000 pid=3806 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=4389b759-1b00-0000-d11c-b313de0e0000 pid=3806 execve guuid=909a1475-1b00-0000-d11c-b313240f0000 pid=3876 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=909a1475-1b00-0000-d11c-b313240f0000 pid=3876 execve guuid=6d795e75-1b00-0000-d11c-b313260f0000 pid=3878 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=6d795e75-1b00-0000-d11c-b313260f0000 pid=3878 clone guuid=1ef89975-1b00-0000-d11c-b313290f0000 pid=3881 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=1ef89975-1b00-0000-d11c-b313290f0000 pid=3881 execve guuid=15a2e775-1b00-0000-d11c-b3132b0f0000 pid=3883 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=15a2e775-1b00-0000-d11c-b3132b0f0000 pid=3883 execve guuid=532f3376-1b00-0000-d11c-b3132d0f0000 pid=3885 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=532f3376-1b00-0000-d11c-b3132d0f0000 pid=3885 execve guuid=006a1590-1b00-0000-d11c-b313870f0000 pid=3975 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=006a1590-1b00-0000-d11c-b313870f0000 pid=3975 execve guuid=d45106ad-1b00-0000-d11c-b313cd0f0000 pid=4045 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=d45106ad-1b00-0000-d11c-b313cd0f0000 pid=4045 execve guuid=62d14bad-1b00-0000-d11c-b313d10f0000 pid=4049 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=62d14bad-1b00-0000-d11c-b313d10f0000 pid=4049 clone guuid=93719bad-1b00-0000-d11c-b313d30f0000 pid=4051 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=93719bad-1b00-0000-d11c-b313d30f0000 pid=4051 execve guuid=29ab01ae-1b00-0000-d11c-b313d70f0000 pid=4055 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=29ab01ae-1b00-0000-d11c-b313d70f0000 pid=4055 execve guuid=21d966ae-1b00-0000-d11c-b313d90f0000 pid=4057 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=21d966ae-1b00-0000-d11c-b313d90f0000 pid=4057 execve guuid=f7a6ccc8-1b00-0000-d11c-b31320100000 pid=4128 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=f7a6ccc8-1b00-0000-d11c-b31320100000 pid=4128 execve guuid=5ed7ea02-1c00-0000-d11c-b31349100000 pid=4169 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=5ed7ea02-1c00-0000-d11c-b31349100000 pid=4169 execve guuid=6afbb703-1c00-0000-d11c-b3134b100000 pid=4171 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=6afbb703-1c00-0000-d11c-b3134b100000 pid=4171 clone guuid=9efa3804-1c00-0000-d11c-b31350100000 pid=4176 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=9efa3804-1c00-0000-d11c-b31350100000 pid=4176 execve guuid=7cc9ef04-1c00-0000-d11c-b31354100000 pid=4180 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=7cc9ef04-1c00-0000-d11c-b31354100000 pid=4180 execve guuid=5f786e05-1c00-0000-d11c-b31356100000 pid=4182 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=5f786e05-1c00-0000-d11c-b31356100000 pid=4182 execve guuid=837eb61f-1c00-0000-d11c-b3139e100000 pid=4254 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=837eb61f-1c00-0000-d11c-b3139e100000 pid=4254 execve guuid=38a48a3b-1c00-0000-d11c-b31311110000 pid=4369 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=38a48a3b-1c00-0000-d11c-b31311110000 pid=4369 execve guuid=ce31033c-1c00-0000-d11c-b31314110000 pid=4372 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=ce31033c-1c00-0000-d11c-b31314110000 pid=4372 clone guuid=b83a503c-1c00-0000-d11c-b31317110000 pid=4375 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=b83a503c-1c00-0000-d11c-b31317110000 pid=4375 execve guuid=3c7dbf3c-1c00-0000-d11c-b31319110000 pid=4377 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=3c7dbf3c-1c00-0000-d11c-b31319110000 pid=4377 execve guuid=89b5223d-1c00-0000-d11c-b3131b110000 pid=4379 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=89b5223d-1c00-0000-d11c-b3131b110000 pid=4379 execve guuid=880da756-1c00-0000-d11c-b31383110000 pid=4483 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=880da756-1c00-0000-d11c-b31383110000 pid=4483 execve guuid=b20e5d72-1c00-0000-d11c-b313d7110000 pid=4567 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=b20e5d72-1c00-0000-d11c-b313d7110000 pid=4567 execve guuid=552aaf72-1c00-0000-d11c-b313d9110000 pid=4569 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=552aaf72-1c00-0000-d11c-b313d9110000 pid=4569 clone guuid=565b1473-1c00-0000-d11c-b313db110000 pid=4571 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=565b1473-1c00-0000-d11c-b313db110000 pid=4571 execve guuid=0af3ae73-1c00-0000-d11c-b313df110000 pid=4575 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=0af3ae73-1c00-0000-d11c-b313df110000 pid=4575 execve guuid=e95d3b74-1c00-0000-d11c-b313e0110000 pid=4576 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=e95d3b74-1c00-0000-d11c-b313e0110000 pid=4576 execve guuid=3f70628e-1c00-0000-d11c-b31345120000 pid=4677 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=3f70628e-1c00-0000-d11c-b31345120000 pid=4677 execve guuid=a7ac39ab-1c00-0000-d11c-b3138e120000 pid=4750 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=a7ac39ab-1c00-0000-d11c-b3138e120000 pid=4750 execve guuid=24ac8bab-1c00-0000-d11c-b31390120000 pid=4752 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=24ac8bab-1c00-0000-d11c-b31390120000 pid=4752 clone guuid=2f83d1ab-1c00-0000-d11c-b31393120000 pid=4755 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=2f83d1ab-1c00-0000-d11c-b31393120000 pid=4755 execve guuid=d55a36ac-1c00-0000-d11c-b31395120000 pid=4757 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=d55a36ac-1c00-0000-d11c-b31395120000 pid=4757 execve guuid=44ca7cac-1c00-0000-d11c-b31397120000 pid=4759 /usr/bin/wget net send-data guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=44ca7cac-1c00-0000-d11c-b31397120000 pid=4759 execve guuid=f3bc64c6-1c00-0000-d11c-b313df120000 pid=4831 /usr/bin/curl net send-data write-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=f3bc64c6-1c00-0000-d11c-b313df120000 pid=4831 execve guuid=7af4cce4-1c00-0000-d11c-b31340130000 pid=4928 /usr/bin/chmod guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=7af4cce4-1c00-0000-d11c-b31340130000 pid=4928 execve guuid=08c119e5-1c00-0000-d11c-b31342130000 pid=4930 /usr/bin/bash guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=08c119e5-1c00-0000-d11c-b31342130000 pid=4930 clone guuid=72b155e5-1c00-0000-d11c-b31345130000 pid=4933 /usr/bin/rm delete-file guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=72b155e5-1c00-0000-d11c-b31345130000 pid=4933 execve guuid=8af999e5-1c00-0000-d11c-b31347130000 pid=4935 /usr/bin/rm guuid=00ef6c23-1a00-0000-d11c-b313900c0000 pid=3216->guuid=8af999e5-1c00-0000-d11c-b31347130000 pid=4935 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=8371c923-1a00-0000-d11c-b313920c0000 pid=3218->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b316e53e-1a00-0000-d11c-b313b00c0000 pid=3248->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=ad76575d-1a00-0000-d11c-b313ed0c0000 pid=3309 /usr/bin/bash guuid=e4882f5d-1a00-0000-d11c-b313ec0c0000 pid=3308->guuid=ad76575d-1a00-0000-d11c-b313ed0c0000 pid=3309 clone guuid=c5bb545e-1a00-0000-d11c-b313f30c0000 pid=3315->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=955e2779-1a00-0000-d11c-b313130d0000 pid=3347->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=57433497-1a00-0000-d11c-b3132b0d0000 pid=3371 /usr/bin/bash guuid=b0820797-1a00-0000-d11c-b3132a0d0000 pid=3370->guuid=57433497-1a00-0000-d11c-b3132b0d0000 pid=3371 clone guuid=23966c98-1a00-0000-d11c-b3132e0d0000 pid=3374->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=6669f9b1-1a00-0000-d11c-b313510d0000 pid=3409->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4210ffcd-1a00-0000-d11c-b313a00d0000 pid=3488 /usr/bin/bash guuid=37f2e5cd-1a00-0000-d11c-b3139f0d0000 pid=3487->guuid=4210ffcd-1a00-0000-d11c-b313a00d0000 pid=3488 clone guuid=a7a1acce-1a00-0000-d11c-b313a50d0000 pid=3493->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=ac11e4e7-1a00-0000-d11c-b313d20d0000 pid=3538->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=40329507-1b00-0000-d11c-b313140e0000 pid=3604 /usr/bin/bash guuid=be756f07-1b00-0000-d11c-b313130e0000 pid=3603->guuid=40329507-1b00-0000-d11c-b313140e0000 pid=3604 clone guuid=02d39908-1b00-0000-d11c-b3131a0e0000 pid=3610->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f0bc8f22-1b00-0000-d11c-b313590e0000 pid=3673->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d305ab3e-1b00-0000-d11c-b313790e0000 pid=3705 /usr/bin/bash guuid=39358f3e-1b00-0000-d11c-b313780e0000 pid=3704->guuid=d305ab3e-1b00-0000-d11c-b313790e0000 pid=3705 clone guuid=bfbb713f-1b00-0000-d11c-b3137c0e0000 pid=3708->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4389b759-1b00-0000-d11c-b313de0e0000 pid=3806->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=bd1d7275-1b00-0000-d11c-b313280f0000 pid=3880 /usr/bin/bash guuid=6d795e75-1b00-0000-d11c-b313260f0000 pid=3878->guuid=bd1d7275-1b00-0000-d11c-b313280f0000 pid=3880 clone guuid=532f3376-1b00-0000-d11c-b3132d0f0000 pid=3885->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=006a1590-1b00-0000-d11c-b313870f0000 pid=3975->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=732f70ad-1b00-0000-d11c-b313d20f0000 pid=4050 /usr/bin/bash guuid=62d14bad-1b00-0000-d11c-b313d10f0000 pid=4049->guuid=732f70ad-1b00-0000-d11c-b313d20f0000 pid=4050 clone guuid=21d966ae-1b00-0000-d11c-b313d90f0000 pid=4057->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f7a6ccc8-1b00-0000-d11c-b31320100000 pid=4128->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=1df6f503-1c00-0000-d11c-b3134d100000 pid=4173 /usr/bin/bash guuid=6afbb703-1c00-0000-d11c-b3134b100000 pid=4171->guuid=1df6f503-1c00-0000-d11c-b3134d100000 pid=4173 clone guuid=5f786e05-1c00-0000-d11c-b31356100000 pid=4182->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=837eb61f-1c00-0000-d11c-b3139e100000 pid=4254->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4613293c-1c00-0000-d11c-b31315110000 pid=4373 /usr/bin/bash guuid=ce31033c-1c00-0000-d11c-b31314110000 pid=4372->guuid=4613293c-1c00-0000-d11c-b31315110000 pid=4373 clone guuid=89b5223d-1c00-0000-d11c-b3131b110000 pid=4379->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=880da756-1c00-0000-d11c-b31383110000 pid=4483->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=6d9fd872-1c00-0000-d11c-b313da110000 pid=4570 /usr/bin/bash guuid=552aaf72-1c00-0000-d11c-b313d9110000 pid=4569->guuid=6d9fd872-1c00-0000-d11c-b313da110000 pid=4570 clone guuid=e95d3b74-1c00-0000-d11c-b313e0110000 pid=4576->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=3f70628e-1c00-0000-d11c-b31345120000 pid=4677->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=f27da6ab-1c00-0000-d11c-b31391120000 pid=4753 /usr/bin/bash guuid=24ac8bab-1c00-0000-d11c-b31390120000 pid=4752->guuid=f27da6ab-1c00-0000-d11c-b31391120000 pid=4753 clone guuid=44ca7cac-1c00-0000-d11c-b31397120000 pid=4759->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f3bc64c6-1c00-0000-d11c-b313df120000 pid=4831->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=be7435e5-1c00-0000-d11c-b31343130000 pid=4931 /usr/bin/bash guuid=08c119e5-1c00-0000-d11c-b31342130000 pid=4930->guuid=be7435e5-1c00-0000-d11c-b31343130000 pid=4931 clone
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 829ffb02a7508158f96c2ea5a5690ed058313eddac02cee2874500a9acc67faa

(this sample)

  
Delivery method
Distributed via web download

Comments