MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8517d2bee75166456f9ca6ffec940af183937471ccbb82f6cfc71194fa287f4a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 8517d2bee75166456f9ca6ffec940af183937471ccbb82f6cfc71194fa287f4a
SHA3-384 hash: d5159b16f9e8c5b7e2cc54362761923fd45990d98c5214e484dd2d9dc5e6d8150b1bd9db635da93bd7add74792a8aceb
SHA1 hash: ed0978c00f5e8917082295eecb431af69058a10e
MD5 hash: e0c8371c8ef89d517ed2b8838245df82
humanhash: johnny-cold-black-jig
File name:1.sh
Download: download sample
File size:6'389 bytes
First seen:2025-07-29 18:19:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:uF3mBbuOBqCvp83N6C122Mk7sIwgnAk9POZD9POZD4ofI8rNwDBmGpiK8Ur843xM:uF3mBbuOBqCvp83N6C122Mk7sIwgnAk5
TLSH T1F8D12FF2B4C5627DDD9FCC3AA151697D2085BA8B2A8F1D6487ED24697C89FCC1C409C3
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mipsn/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arcn/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i468n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i686n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86_64n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mpsln/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.armn/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm5n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm6n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm7n/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.ppcn/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.spcn/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.m68kn/an/an/a
http://176.65.148.194/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.sh4n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=cc6b114c-1900-0000-fbf5-01f7e0090000 pid=2528 /usr/bin/sudo guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534 /tmp/sample.bin guuid=cc6b114c-1900-0000-fbf5-01f7e0090000 pid=2528->guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534 execve guuid=7e59804e-1900-0000-fbf5-01f7e8090000 pid=2536 /usr/bin/cp guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=7e59804e-1900-0000-fbf5-01f7e8090000 pid=2536 execve guuid=72c70c56-1900-0000-fbf5-01f7f6090000 pid=2550 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=72c70c56-1900-0000-fbf5-01f7f6090000 pid=2550 execve guuid=0aebfa5a-1900-0000-fbf5-01f7ff090000 pid=2559 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=0aebfa5a-1900-0000-fbf5-01f7ff090000 pid=2559 execve guuid=eae7bc65-1900-0000-fbf5-01f7160a0000 pid=2582 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=eae7bc65-1900-0000-fbf5-01f7160a0000 pid=2582 execve guuid=837c0766-1900-0000-fbf5-01f7180a0000 pid=2584 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=837c0766-1900-0000-fbf5-01f7180a0000 pid=2584 clone guuid=540d3e66-1900-0000-fbf5-01f71a0a0000 pid=2586 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=540d3e66-1900-0000-fbf5-01f71a0a0000 pid=2586 execve guuid=a0c8b766-1900-0000-fbf5-01f71c0a0000 pid=2588 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a0c8b766-1900-0000-fbf5-01f71c0a0000 pid=2588 execve guuid=96fd4869-1900-0000-fbf5-01f7270a0000 pid=2599 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=96fd4869-1900-0000-fbf5-01f7270a0000 pid=2599 execve guuid=b1f89a6e-1900-0000-fbf5-01f7380a0000 pid=2616 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=b1f89a6e-1900-0000-fbf5-01f7380a0000 pid=2616 execve guuid=556ce06e-1900-0000-fbf5-01f7390a0000 pid=2617 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=556ce06e-1900-0000-fbf5-01f7390a0000 pid=2617 clone guuid=579a016f-1900-0000-fbf5-01f73b0a0000 pid=2619 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=579a016f-1900-0000-fbf5-01f73b0a0000 pid=2619 execve guuid=4fa24f6f-1900-0000-fbf5-01f73c0a0000 pid=2620 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=4fa24f6f-1900-0000-fbf5-01f73c0a0000 pid=2620 execve guuid=8a033673-1900-0000-fbf5-01f7460a0000 pid=2630 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=8a033673-1900-0000-fbf5-01f7460a0000 pid=2630 execve guuid=d0e1a976-1900-0000-fbf5-01f7530a0000 pid=2643 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=d0e1a976-1900-0000-fbf5-01f7530a0000 pid=2643 execve guuid=5402fa76-1900-0000-fbf5-01f7550a0000 pid=2645 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=5402fa76-1900-0000-fbf5-01f7550a0000 pid=2645 clone guuid=dd842a77-1900-0000-fbf5-01f7570a0000 pid=2647 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=dd842a77-1900-0000-fbf5-01f7570a0000 pid=2647 execve guuid=6c798b77-1900-0000-fbf5-01f7590a0000 pid=2649 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=6c798b77-1900-0000-fbf5-01f7590a0000 pid=2649 execve guuid=331b7f7b-1900-0000-fbf5-01f7650a0000 pid=2661 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=331b7f7b-1900-0000-fbf5-01f7650a0000 pid=2661 execve guuid=cc1f5082-1900-0000-fbf5-01f7780a0000 pid=2680 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=cc1f5082-1900-0000-fbf5-01f7780a0000 pid=2680 execve guuid=6904f182-1900-0000-fbf5-01f77b0a0000 pid=2683 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=6904f182-1900-0000-fbf5-01f77b0a0000 pid=2683 clone guuid=a3716083-1900-0000-fbf5-01f77e0a0000 pid=2686 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a3716083-1900-0000-fbf5-01f77e0a0000 pid=2686 execve guuid=0448c783-1900-0000-fbf5-01f7800a0000 pid=2688 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=0448c783-1900-0000-fbf5-01f7800a0000 pid=2688 execve guuid=82c06987-1900-0000-fbf5-01f78a0a0000 pid=2698 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=82c06987-1900-0000-fbf5-01f78a0a0000 pid=2698 execve guuid=5fb41c8c-1900-0000-fbf5-01f7930a0000 pid=2707 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=5fb41c8c-1900-0000-fbf5-01f7930a0000 pid=2707 execve guuid=dc700d8d-1900-0000-fbf5-01f7960a0000 pid=2710 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=dc700d8d-1900-0000-fbf5-01f7960a0000 pid=2710 clone guuid=8abe538d-1900-0000-fbf5-01f7980a0000 pid=2712 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=8abe538d-1900-0000-fbf5-01f7980a0000 pid=2712 execve guuid=1f4ab98d-1900-0000-fbf5-01f7990a0000 pid=2713 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=1f4ab98d-1900-0000-fbf5-01f7990a0000 pid=2713 execve guuid=241dc891-1900-0000-fbf5-01f7a50a0000 pid=2725 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=241dc891-1900-0000-fbf5-01f7a50a0000 pid=2725 execve guuid=76130998-1900-0000-fbf5-01f7b70a0000 pid=2743 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=76130998-1900-0000-fbf5-01f7b70a0000 pid=2743 execve guuid=5f066598-1900-0000-fbf5-01f7b90a0000 pid=2745 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=5f066598-1900-0000-fbf5-01f7b90a0000 pid=2745 clone guuid=89a4a798-1900-0000-fbf5-01f7bb0a0000 pid=2747 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=89a4a798-1900-0000-fbf5-01f7bb0a0000 pid=2747 execve guuid=b40e2099-1900-0000-fbf5-01f7bd0a0000 pid=2749 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=b40e2099-1900-0000-fbf5-01f7bd0a0000 pid=2749 execve guuid=948a6d9c-1900-0000-fbf5-01f7c60a0000 pid=2758 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=948a6d9c-1900-0000-fbf5-01f7c60a0000 pid=2758 execve guuid=e1e659a0-1900-0000-fbf5-01f7d30a0000 pid=2771 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=e1e659a0-1900-0000-fbf5-01f7d30a0000 pid=2771 execve guuid=7d779ea0-1900-0000-fbf5-01f7d50a0000 pid=2773 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=7d779ea0-1900-0000-fbf5-01f7d50a0000 pid=2773 clone guuid=ee8ccaa0-1900-0000-fbf5-01f7d70a0000 pid=2775 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=ee8ccaa0-1900-0000-fbf5-01f7d70a0000 pid=2775 execve guuid=26bd13a1-1900-0000-fbf5-01f7d90a0000 pid=2777 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=26bd13a1-1900-0000-fbf5-01f7d90a0000 pid=2777 execve guuid=5548c1a3-1900-0000-fbf5-01f7e20a0000 pid=2786 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=5548c1a3-1900-0000-fbf5-01f7e20a0000 pid=2786 execve guuid=fa6d79a7-1900-0000-fbf5-01f7ea0a0000 pid=2794 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=fa6d79a7-1900-0000-fbf5-01f7ea0a0000 pid=2794 execve guuid=5303c3a7-1900-0000-fbf5-01f7ec0a0000 pid=2796 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=5303c3a7-1900-0000-fbf5-01f7ec0a0000 pid=2796 clone guuid=bac0e7a7-1900-0000-fbf5-01f7ed0a0000 pid=2797 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=bac0e7a7-1900-0000-fbf5-01f7ed0a0000 pid=2797 execve guuid=152e52a8-1900-0000-fbf5-01f7ee0a0000 pid=2798 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=152e52a8-1900-0000-fbf5-01f7ee0a0000 pid=2798 execve guuid=a8310dab-1900-0000-fbf5-01f7f40a0000 pid=2804 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a8310dab-1900-0000-fbf5-01f7f40a0000 pid=2804 execve guuid=8e7939af-1900-0000-fbf5-01f7ff0a0000 pid=2815 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=8e7939af-1900-0000-fbf5-01f7ff0a0000 pid=2815 execve guuid=a09485af-1900-0000-fbf5-01f7000b0000 pid=2816 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a09485af-1900-0000-fbf5-01f7000b0000 pid=2816 clone guuid=4e6ca7af-1900-0000-fbf5-01f7010b0000 pid=2817 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=4e6ca7af-1900-0000-fbf5-01f7010b0000 pid=2817 execve guuid=1ba2fdaf-1900-0000-fbf5-01f7030b0000 pid=2819 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=1ba2fdaf-1900-0000-fbf5-01f7030b0000 pid=2819 execve guuid=298009b3-1900-0000-fbf5-01f70b0b0000 pid=2827 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=298009b3-1900-0000-fbf5-01f70b0b0000 pid=2827 execve guuid=9957f1b6-1900-0000-fbf5-01f7170b0000 pid=2839 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=9957f1b6-1900-0000-fbf5-01f7170b0000 pid=2839 execve guuid=a17c32b7-1900-0000-fbf5-01f7190b0000 pid=2841 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a17c32b7-1900-0000-fbf5-01f7190b0000 pid=2841 clone guuid=b41c58b7-1900-0000-fbf5-01f71b0b0000 pid=2843 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=b41c58b7-1900-0000-fbf5-01f71b0b0000 pid=2843 execve guuid=252ba8b7-1900-0000-fbf5-01f71d0b0000 pid=2845 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=252ba8b7-1900-0000-fbf5-01f71d0b0000 pid=2845 execve guuid=a1c5a0ba-1900-0000-fbf5-01f7240b0000 pid=2852 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a1c5a0ba-1900-0000-fbf5-01f7240b0000 pid=2852 execve guuid=0f17dcbe-1900-0000-fbf5-01f72e0b0000 pid=2862 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=0f17dcbe-1900-0000-fbf5-01f72e0b0000 pid=2862 execve guuid=11bc2bbf-1900-0000-fbf5-01f7300b0000 pid=2864 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=11bc2bbf-1900-0000-fbf5-01f7300b0000 pid=2864 clone guuid=0e804fbf-1900-0000-fbf5-01f7320b0000 pid=2866 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=0e804fbf-1900-0000-fbf5-01f7320b0000 pid=2866 execve guuid=f322a5bf-1900-0000-fbf5-01f7330b0000 pid=2867 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=f322a5bf-1900-0000-fbf5-01f7330b0000 pid=2867 execve guuid=e3899dc2-1900-0000-fbf5-01f73b0b0000 pid=2875 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=e3899dc2-1900-0000-fbf5-01f73b0b0000 pid=2875 execve guuid=f0667fc6-1900-0000-fbf5-01f7430b0000 pid=2883 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=f0667fc6-1900-0000-fbf5-01f7430b0000 pid=2883 execve guuid=c44de0c6-1900-0000-fbf5-01f7450b0000 pid=2885 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=c44de0c6-1900-0000-fbf5-01f7450b0000 pid=2885 clone guuid=a2670ec7-1900-0000-fbf5-01f7460b0000 pid=2886 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a2670ec7-1900-0000-fbf5-01f7460b0000 pid=2886 execve guuid=509079c7-1900-0000-fbf5-01f7480b0000 pid=2888 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=509079c7-1900-0000-fbf5-01f7480b0000 pid=2888 execve guuid=5f0a1aca-1900-0000-fbf5-01f7500b0000 pid=2896 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=5f0a1aca-1900-0000-fbf5-01f7500b0000 pid=2896 execve guuid=e761fdcd-1900-0000-fbf5-01f75b0b0000 pid=2907 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=e761fdcd-1900-0000-fbf5-01f75b0b0000 pid=2907 execve guuid=34db46ce-1900-0000-fbf5-01f75d0b0000 pid=2909 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=34db46ce-1900-0000-fbf5-01f75d0b0000 pid=2909 clone guuid=a81669ce-1900-0000-fbf5-01f75e0b0000 pid=2910 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=a81669ce-1900-0000-fbf5-01f75e0b0000 pid=2910 execve guuid=9009b2ce-1900-0000-fbf5-01f7600b0000 pid=2912 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=9009b2ce-1900-0000-fbf5-01f7600b0000 pid=2912 execve guuid=8e264dd1-1900-0000-fbf5-01f7680b0000 pid=2920 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=8e264dd1-1900-0000-fbf5-01f7680b0000 pid=2920 execve guuid=831b9ad4-1900-0000-fbf5-01f7740b0000 pid=2932 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=831b9ad4-1900-0000-fbf5-01f7740b0000 pid=2932 execve guuid=d2cbefd4-1900-0000-fbf5-01f7760b0000 pid=2934 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=d2cbefd4-1900-0000-fbf5-01f7760b0000 pid=2934 clone guuid=3c7e14d5-1900-0000-fbf5-01f7780b0000 pid=2936 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=3c7e14d5-1900-0000-fbf5-01f7780b0000 pid=2936 execve guuid=550760d5-1900-0000-fbf5-01f77a0b0000 pid=2938 /usr/bin/wget net send-data guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=550760d5-1900-0000-fbf5-01f77a0b0000 pid=2938 execve guuid=594d0fd8-1900-0000-fbf5-01f7840b0000 pid=2948 /usr/bin/curl net send-data write-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=594d0fd8-1900-0000-fbf5-01f7840b0000 pid=2948 execve guuid=b4897cdb-1900-0000-fbf5-01f7910b0000 pid=2961 /usr/bin/chmod guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=b4897cdb-1900-0000-fbf5-01f7910b0000 pid=2961 execve guuid=ced5bddb-1900-0000-fbf5-01f7930b0000 pid=2963 /usr/bin/bash guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=ced5bddb-1900-0000-fbf5-01f7930b0000 pid=2963 clone guuid=c7b8dddb-1900-0000-fbf5-01f7950b0000 pid=2965 /usr/bin/rm delete-file guuid=d4f3ee4d-1900-0000-fbf5-01f7e6090000 pid=2534->guuid=c7b8dddb-1900-0000-fbf5-01f7950b0000 pid=2965 execve 61a1eecf-c14c-5f53-bf3e-19b35521f0f4 176.65.148.194:80 guuid=72c70c56-1900-0000-fbf5-01f7f6090000 pid=2550->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 214B guuid=0aebfa5a-1900-0000-fbf5-01f7ff090000 pid=2559->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 163B guuid=a0c8b766-1900-0000-fbf5-01f71c0a0000 pid=2588->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=96fd4869-1900-0000-fbf5-01f7270a0000 pid=2599->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=4fa24f6f-1900-0000-fbf5-01f73c0a0000 pid=2620->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 214B guuid=8a033673-1900-0000-fbf5-01f7460a0000 pid=2630->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 163B guuid=6c798b77-1900-0000-fbf5-01f7590a0000 pid=2649->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=331b7f7b-1900-0000-fbf5-01f7650a0000 pid=2661->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=0448c783-1900-0000-fbf5-01f7800a0000 pid=2688->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=82c06987-1900-0000-fbf5-01f78a0a0000 pid=2698->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=1f4ab98d-1900-0000-fbf5-01f7990a0000 pid=2713->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 217B guuid=241dc891-1900-0000-fbf5-01f7a50a0000 pid=2725->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 166B guuid=b40e2099-1900-0000-fbf5-01f7bd0a0000 pid=2749->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=948a6d9c-1900-0000-fbf5-01f7c60a0000 pid=2758->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=26bd13a1-1900-0000-fbf5-01f7d90a0000 pid=2777->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 214B guuid=5548c1a3-1900-0000-fbf5-01f7e20a0000 pid=2786->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 163B guuid=152e52a8-1900-0000-fbf5-01f7ee0a0000 pid=2798->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=a8310dab-1900-0000-fbf5-01f7f40a0000 pid=2804->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=1ba2fdaf-1900-0000-fbf5-01f7030b0000 pid=2819->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=298009b3-1900-0000-fbf5-01f70b0b0000 pid=2827->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=252ba8b7-1900-0000-fbf5-01f71d0b0000 pid=2845->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=a1c5a0ba-1900-0000-fbf5-01f7240b0000 pid=2852->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=f322a5bf-1900-0000-fbf5-01f7330b0000 pid=2867->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 214B guuid=e3899dc2-1900-0000-fbf5-01f73b0b0000 pid=2875->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 163B guuid=509079c7-1900-0000-fbf5-01f7480b0000 pid=2888->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 214B guuid=5f0a1aca-1900-0000-fbf5-01f7500b0000 pid=2896->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 163B guuid=9009b2ce-1900-0000-fbf5-01f7600b0000 pid=2912->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 215B guuid=8e264dd1-1900-0000-fbf5-01f7680b0000 pid=2920->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 164B guuid=550760d5-1900-0000-fbf5-01f77a0b0000 pid=2938->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 214B guuid=594d0fd8-1900-0000-fbf5-01f7840b0000 pid=2948->61a1eecf-c14c-5f53-bf3e-19b35521f0f4 send: 163B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-07-29 18:20:24 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8517d2bee75166456f9ca6ffec940af183937471ccbb82f6cfc71194fa287f4a

(this sample)

  
Delivery method
Distributed via web download

Comments