MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8561c900bf144fcdf512eefa9cdb8c7c22b1ff4007707a242c1d3f1b332cd558. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 8561c900bf144fcdf512eefa9cdb8c7c22b1ff4007707a242c1d3f1b332cd558
SHA3-384 hash: f944fc7ac15cf1e76b9b353114672d3c57bb0a2beb481459e0be16943acd2e64a01d0df777a95eb7d8e927672ab380c9
SHA1 hash: 41cdfef2ea0f16a404792c9b85030142fdf6e3c7
MD5 hash: 3fcd68d1177be4f73d9f27d4e883b13c
humanhash: alpha-fillet-angel-may
File name:p
Download: download sample
File size:830 bytes
First seen:2026-06-02 01:26:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaKIlotevsNPZjVA7:e9Qp+MsKIloo0NPZj27
TLSH T13D01AFC9C111D75080C9E85EA2E772807411C3CF65864BA87F8C843D9BA97487159F84
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/ojjn/an/aelf ua-wget
http://188.132.232.81/L4RAn/an/aelf ua-wget
http://188.132.232.81/fuFn/an/aelf ua-wget
http://188.132.232.81/9sIn/an/aelf ua-wget
http://188.132.232.81/TxJMn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-01T22:37:00Z UTC
Last seen:
2026-06-02T09:00:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f52c183d-1700-0000-deb1-e3f93c0f0000 pid=3900 /usr/bin/sudo guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907 /tmp/sample.bin write-file guuid=f52c183d-1700-0000-deb1-e3f93c0f0000 pid=3900->guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907 execve guuid=a108243f-1700-0000-deb1-e3f9450f0000 pid=3909 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a108243f-1700-0000-deb1-e3f9450f0000 pid=3909 execve guuid=35f28e3f-1700-0000-deb1-e3f9480f0000 pid=3912 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=35f28e3f-1700-0000-deb1-e3f9480f0000 pid=3912 execve guuid=1b33ef3f-1700-0000-deb1-e3f94b0f0000 pid=3915 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=1b33ef3f-1700-0000-deb1-e3f94b0f0000 pid=3915 execve guuid=099f4940-1700-0000-deb1-e3f94f0f0000 pid=3919 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=099f4940-1700-0000-deb1-e3f94f0f0000 pid=3919 execve guuid=83a60441-1700-0000-deb1-e3f9540f0000 pid=3924 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=83a60441-1700-0000-deb1-e3f9540f0000 pid=3924 execve guuid=4b355941-1700-0000-deb1-e3f9580f0000 pid=3928 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=4b355941-1700-0000-deb1-e3f9580f0000 pid=3928 execve guuid=4e4eaf41-1700-0000-deb1-e3f95a0f0000 pid=3930 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=4e4eaf41-1700-0000-deb1-e3f95a0f0000 pid=3930 execve guuid=c75e0542-1700-0000-deb1-e3f95c0f0000 pid=3932 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=c75e0542-1700-0000-deb1-e3f95c0f0000 pid=3932 execve guuid=43026942-1700-0000-deb1-e3f9600f0000 pid=3936 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=43026942-1700-0000-deb1-e3f9600f0000 pid=3936 execve guuid=b516cb42-1700-0000-deb1-e3f9640f0000 pid=3940 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=b516cb42-1700-0000-deb1-e3f9640f0000 pid=3940 execve guuid=c7849143-1700-0000-deb1-e3f9660f0000 pid=3942 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=c7849143-1700-0000-deb1-e3f9660f0000 pid=3942 execve guuid=3c7cee43-1700-0000-deb1-e3f9680f0000 pid=3944 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3c7cee43-1700-0000-deb1-e3f9680f0000 pid=3944 execve guuid=18145944-1700-0000-deb1-e3f96b0f0000 pid=3947 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=18145944-1700-0000-deb1-e3f96b0f0000 pid=3947 execve guuid=75bb3445-1700-0000-deb1-e3f9700f0000 pid=3952 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=75bb3445-1700-0000-deb1-e3f9700f0000 pid=3952 execve guuid=cab8a145-1700-0000-deb1-e3f9720f0000 pid=3954 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=cab8a145-1700-0000-deb1-e3f9720f0000 pid=3954 execve guuid=57280346-1700-0000-deb1-e3f9750f0000 pid=3957 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=57280346-1700-0000-deb1-e3f9750f0000 pid=3957 execve guuid=fb346346-1700-0000-deb1-e3f9760f0000 pid=3958 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=fb346346-1700-0000-deb1-e3f9760f0000 pid=3958 execve guuid=0abdbf46-1700-0000-deb1-e3f97a0f0000 pid=3962 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=0abdbf46-1700-0000-deb1-e3f97a0f0000 pid=3962 execve guuid=a0b42747-1700-0000-deb1-e3f97d0f0000 pid=3965 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a0b42747-1700-0000-deb1-e3f97d0f0000 pid=3965 execve guuid=3b3f8147-1700-0000-deb1-e3f9810f0000 pid=3969 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3b3f8147-1700-0000-deb1-e3f9810f0000 pid=3969 execve guuid=64c6df47-1700-0000-deb1-e3f9830f0000 pid=3971 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=64c6df47-1700-0000-deb1-e3f9830f0000 pid=3971 execve guuid=33a83d48-1700-0000-deb1-e3f9870f0000 pid=3975 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=33a83d48-1700-0000-deb1-e3f9870f0000 pid=3975 execve guuid=56a0a248-1700-0000-deb1-e3f98b0f0000 pid=3979 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=56a0a248-1700-0000-deb1-e3f98b0f0000 pid=3979 execve guuid=0334ff48-1700-0000-deb1-e3f98d0f0000 pid=3981 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=0334ff48-1700-0000-deb1-e3f98d0f0000 pid=3981 execve guuid=df9a5949-1700-0000-deb1-e3f9900f0000 pid=3984 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=df9a5949-1700-0000-deb1-e3f9900f0000 pid=3984 execve guuid=e67abc49-1700-0000-deb1-e3f9920f0000 pid=3986 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e67abc49-1700-0000-deb1-e3f9920f0000 pid=3986 execve guuid=8f3b174a-1700-0000-deb1-e3f9940f0000 pid=3988 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=8f3b174a-1700-0000-deb1-e3f9940f0000 pid=3988 execve guuid=aae8724a-1700-0000-deb1-e3f9970f0000 pid=3991 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=aae8724a-1700-0000-deb1-e3f9970f0000 pid=3991 execve guuid=e340cf4a-1700-0000-deb1-e3f9990f0000 pid=3993 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e340cf4a-1700-0000-deb1-e3f9990f0000 pid=3993 execve guuid=c78a344b-1700-0000-deb1-e3f99d0f0000 pid=3997 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=c78a344b-1700-0000-deb1-e3f99d0f0000 pid=3997 execve guuid=7122964b-1700-0000-deb1-e3f9a00f0000 pid=4000 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=7122964b-1700-0000-deb1-e3f9a00f0000 pid=4000 execve guuid=4b9dea4b-1700-0000-deb1-e3f9a20f0000 pid=4002 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=4b9dea4b-1700-0000-deb1-e3f9a20f0000 pid=4002 execve guuid=a9e8444c-1700-0000-deb1-e3f9a50f0000 pid=4005 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a9e8444c-1700-0000-deb1-e3f9a50f0000 pid=4005 execve guuid=46eba74c-1700-0000-deb1-e3f9a70f0000 pid=4007 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=46eba74c-1700-0000-deb1-e3f9a70f0000 pid=4007 execve guuid=fbca034d-1700-0000-deb1-e3f9aa0f0000 pid=4010 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=fbca034d-1700-0000-deb1-e3f9aa0f0000 pid=4010 execve guuid=90ae604d-1700-0000-deb1-e3f9ac0f0000 pid=4012 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=90ae604d-1700-0000-deb1-e3f9ac0f0000 pid=4012 execve guuid=def3c74d-1700-0000-deb1-e3f9af0f0000 pid=4015 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=def3c74d-1700-0000-deb1-e3f9af0f0000 pid=4015 execve guuid=7483204e-1700-0000-deb1-e3f9b30f0000 pid=4019 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=7483204e-1700-0000-deb1-e3f9b30f0000 pid=4019 execve guuid=c6cb7a4e-1700-0000-deb1-e3f9b50f0000 pid=4021 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=c6cb7a4e-1700-0000-deb1-e3f9b50f0000 pid=4021 execve guuid=b532d34e-1700-0000-deb1-e3f9b80f0000 pid=4024 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=b532d34e-1700-0000-deb1-e3f9b80f0000 pid=4024 execve guuid=ab152a4f-1700-0000-deb1-e3f9bb0f0000 pid=4027 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ab152a4f-1700-0000-deb1-e3f9bb0f0000 pid=4027 execve guuid=3f52804f-1700-0000-deb1-e3f9bf0f0000 pid=4031 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3f52804f-1700-0000-deb1-e3f9bf0f0000 pid=4031 execve guuid=7bc2d84f-1700-0000-deb1-e3f9c30f0000 pid=4035 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=7bc2d84f-1700-0000-deb1-e3f9c30f0000 pid=4035 execve guuid=25813350-1700-0000-deb1-e3f9c50f0000 pid=4037 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=25813350-1700-0000-deb1-e3f9c50f0000 pid=4037 execve guuid=d26d8d50-1700-0000-deb1-e3f9c70f0000 pid=4039 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=d26d8d50-1700-0000-deb1-e3f9c70f0000 pid=4039 execve guuid=3528ed50-1700-0000-deb1-e3f9ca0f0000 pid=4042 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3528ed50-1700-0000-deb1-e3f9ca0f0000 pid=4042 execve guuid=674c4951-1700-0000-deb1-e3f9cc0f0000 pid=4044 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=674c4951-1700-0000-deb1-e3f9cc0f0000 pid=4044 execve guuid=fbbba551-1700-0000-deb1-e3f9cf0f0000 pid=4047 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=fbbba551-1700-0000-deb1-e3f9cf0f0000 pid=4047 execve guuid=e261fe51-1700-0000-deb1-e3f9d10f0000 pid=4049 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e261fe51-1700-0000-deb1-e3f9d10f0000 pid=4049 execve guuid=006d5d52-1700-0000-deb1-e3f9d50f0000 pid=4053 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=006d5d52-1700-0000-deb1-e3f9d50f0000 pid=4053 execve guuid=a1bbbe52-1700-0000-deb1-e3f9d70f0000 pid=4055 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a1bbbe52-1700-0000-deb1-e3f9d70f0000 pid=4055 execve guuid=9e181e53-1700-0000-deb1-e3f9da0f0000 pid=4058 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=9e181e53-1700-0000-deb1-e3f9da0f0000 pid=4058 execve guuid=216b7f53-1700-0000-deb1-e3f9dd0f0000 pid=4061 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=216b7f53-1700-0000-deb1-e3f9dd0f0000 pid=4061 execve guuid=e58fe153-1700-0000-deb1-e3f9df0f0000 pid=4063 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e58fe153-1700-0000-deb1-e3f9df0f0000 pid=4063 execve guuid=e3ca4154-1700-0000-deb1-e3f9e10f0000 pid=4065 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e3ca4154-1700-0000-deb1-e3f9e10f0000 pid=4065 execve guuid=4964aa54-1700-0000-deb1-e3f9e40f0000 pid=4068 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=4964aa54-1700-0000-deb1-e3f9e40f0000 pid=4068 execve guuid=5bd10e55-1700-0000-deb1-e3f9e60f0000 pid=4070 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=5bd10e55-1700-0000-deb1-e3f9e60f0000 pid=4070 execve guuid=4a167855-1700-0000-deb1-e3f9e80f0000 pid=4072 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=4a167855-1700-0000-deb1-e3f9e80f0000 pid=4072 execve guuid=781ddb55-1700-0000-deb1-e3f9ec0f0000 pid=4076 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=781ddb55-1700-0000-deb1-e3f9ec0f0000 pid=4076 execve guuid=e7543a56-1700-0000-deb1-e3f9f00f0000 pid=4080 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e7543a56-1700-0000-deb1-e3f9f00f0000 pid=4080 execve guuid=f1cc8556-1700-0000-deb1-e3f9f20f0000 pid=4082 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=f1cc8556-1700-0000-deb1-e3f9f20f0000 pid=4082 execve guuid=aa38e156-1700-0000-deb1-e3f9f40f0000 pid=4084 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=aa38e156-1700-0000-deb1-e3f9f40f0000 pid=4084 execve guuid=a4383b57-1700-0000-deb1-e3f9f80f0000 pid=4088 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a4383b57-1700-0000-deb1-e3f9f80f0000 pid=4088 execve guuid=79859857-1700-0000-deb1-e3f9fc0f0000 pid=4092 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=79859857-1700-0000-deb1-e3f9fc0f0000 pid=4092 execve guuid=0ce2f457-1700-0000-deb1-e3f9fe0f0000 pid=4094 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=0ce2f457-1700-0000-deb1-e3f9fe0f0000 pid=4094 execve guuid=248b5558-1700-0000-deb1-e3f901100000 pid=4097 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=248b5558-1700-0000-deb1-e3f901100000 pid=4097 execve guuid=f390ab58-1700-0000-deb1-e3f903100000 pid=4099 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=f390ab58-1700-0000-deb1-e3f903100000 pid=4099 execve guuid=c5440659-1700-0000-deb1-e3f906100000 pid=4102 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=c5440659-1700-0000-deb1-e3f906100000 pid=4102 execve guuid=14065e59-1700-0000-deb1-e3f908100000 pid=4104 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=14065e59-1700-0000-deb1-e3f908100000 pid=4104 execve guuid=30febe59-1700-0000-deb1-e3f90a100000 pid=4106 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=30febe59-1700-0000-deb1-e3f90a100000 pid=4106 execve guuid=ff18195a-1700-0000-deb1-e3f90c100000 pid=4108 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ff18195a-1700-0000-deb1-e3f90c100000 pid=4108 execve guuid=cb14735a-1700-0000-deb1-e3f910100000 pid=4112 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=cb14735a-1700-0000-deb1-e3f910100000 pid=4112 execve guuid=f899d05a-1700-0000-deb1-e3f911100000 pid=4113 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=f899d05a-1700-0000-deb1-e3f911100000 pid=4113 execve guuid=120b305b-1700-0000-deb1-e3f915100000 pid=4117 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=120b305b-1700-0000-deb1-e3f915100000 pid=4117 execve guuid=1fb78c5b-1700-0000-deb1-e3f919100000 pid=4121 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=1fb78c5b-1700-0000-deb1-e3f919100000 pid=4121 execve guuid=9434ed5b-1700-0000-deb1-e3f91a100000 pid=4122 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=9434ed5b-1700-0000-deb1-e3f91a100000 pid=4122 execve guuid=4f834c5c-1700-0000-deb1-e3f91e100000 pid=4126 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=4f834c5c-1700-0000-deb1-e3f91e100000 pid=4126 execve guuid=1b74b15c-1700-0000-deb1-e3f922100000 pid=4130 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=1b74b15c-1700-0000-deb1-e3f922100000 pid=4130 execve guuid=a8930f5d-1700-0000-deb1-e3f925100000 pid=4133 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a8930f5d-1700-0000-deb1-e3f925100000 pid=4133 execve guuid=96b56d5d-1700-0000-deb1-e3f927100000 pid=4135 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=96b56d5d-1700-0000-deb1-e3f927100000 pid=4135 execve guuid=16ece95d-1700-0000-deb1-e3f92a100000 pid=4138 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=16ece95d-1700-0000-deb1-e3f92a100000 pid=4138 execve guuid=d16bbf5e-1700-0000-deb1-e3f92e100000 pid=4142 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=d16bbf5e-1700-0000-deb1-e3f92e100000 pid=4142 execve guuid=3b9f2e5f-1700-0000-deb1-e3f932100000 pid=4146 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3b9f2e5f-1700-0000-deb1-e3f932100000 pid=4146 execve guuid=f0128f5f-1700-0000-deb1-e3f936100000 pid=4150 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=f0128f5f-1700-0000-deb1-e3f936100000 pid=4150 execve guuid=2f42f15f-1700-0000-deb1-e3f938100000 pid=4152 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=2f42f15f-1700-0000-deb1-e3f938100000 pid=4152 execve guuid=2d375660-1700-0000-deb1-e3f93a100000 pid=4154 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=2d375660-1700-0000-deb1-e3f93a100000 pid=4154 execve guuid=e1ddbe60-1700-0000-deb1-e3f93d100000 pid=4157 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e1ddbe60-1700-0000-deb1-e3f93d100000 pid=4157 execve guuid=07932861-1700-0000-deb1-e3f93f100000 pid=4159 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=07932861-1700-0000-deb1-e3f93f100000 pid=4159 execve guuid=a48f9461-1700-0000-deb1-e3f942100000 pid=4162 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=a48f9461-1700-0000-deb1-e3f942100000 pid=4162 execve guuid=23fc1062-1700-0000-deb1-e3f944100000 pid=4164 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=23fc1062-1700-0000-deb1-e3f944100000 pid=4164 execve guuid=c2d67862-1700-0000-deb1-e3f948100000 pid=4168 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=c2d67862-1700-0000-deb1-e3f948100000 pid=4168 execve guuid=452dee62-1700-0000-deb1-e3f94c100000 pid=4172 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=452dee62-1700-0000-deb1-e3f94c100000 pid=4172 execve guuid=de425063-1700-0000-deb1-e3f94e100000 pid=4174 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=de425063-1700-0000-deb1-e3f94e100000 pid=4174 execve guuid=2b14b063-1700-0000-deb1-e3f951100000 pid=4177 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=2b14b063-1700-0000-deb1-e3f951100000 pid=4177 execve guuid=73c70f64-1700-0000-deb1-e3f953100000 pid=4179 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=73c70f64-1700-0000-deb1-e3f953100000 pid=4179 execve guuid=5363b564-1700-0000-deb1-e3f956100000 pid=4182 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=5363b564-1700-0000-deb1-e3f956100000 pid=4182 execve guuid=ed9b1165-1700-0000-deb1-e3f957100000 pid=4183 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ed9b1165-1700-0000-deb1-e3f957100000 pid=4183 execve guuid=e4037c65-1700-0000-deb1-e3f958100000 pid=4184 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e4037c65-1700-0000-deb1-e3f958100000 pid=4184 execve guuid=f9e9df65-1700-0000-deb1-e3f959100000 pid=4185 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=f9e9df65-1700-0000-deb1-e3f959100000 pid=4185 execve guuid=ea108566-1700-0000-deb1-e3f95a100000 pid=4186 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ea108566-1700-0000-deb1-e3f95a100000 pid=4186 execve guuid=bea6e766-1700-0000-deb1-e3f95b100000 pid=4187 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=bea6e766-1700-0000-deb1-e3f95b100000 pid=4187 execve guuid=6a415267-1700-0000-deb1-e3f95d100000 pid=4189 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=6a415267-1700-0000-deb1-e3f95d100000 pid=4189 execve guuid=9f66b767-1700-0000-deb1-e3f95f100000 pid=4191 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=9f66b767-1700-0000-deb1-e3f95f100000 pid=4191 execve guuid=8f881668-1700-0000-deb1-e3f963100000 pid=4195 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=8f881668-1700-0000-deb1-e3f963100000 pid=4195 execve guuid=08528068-1700-0000-deb1-e3f967100000 pid=4199 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=08528068-1700-0000-deb1-e3f967100000 pid=4199 execve guuid=8728df68-1700-0000-deb1-e3f969100000 pid=4201 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=8728df68-1700-0000-deb1-e3f969100000 pid=4201 execve guuid=d4873b69-1700-0000-deb1-e3f96c100000 pid=4204 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=d4873b69-1700-0000-deb1-e3f96c100000 pid=4204 execve guuid=6e9e9769-1700-0000-deb1-e3f96e100000 pid=4206 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=6e9e9769-1700-0000-deb1-e3f96e100000 pid=4206 execve guuid=8c22f469-1700-0000-deb1-e3f971100000 pid=4209 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=8c22f469-1700-0000-deb1-e3f971100000 pid=4209 execve guuid=095a646a-1700-0000-deb1-e3f974100000 pid=4212 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=095a646a-1700-0000-deb1-e3f974100000 pid=4212 execve guuid=b382c26a-1700-0000-deb1-e3f975100000 pid=4213 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=b382c26a-1700-0000-deb1-e3f975100000 pid=4213 execve guuid=253d256b-1700-0000-deb1-e3f979100000 pid=4217 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=253d256b-1700-0000-deb1-e3f979100000 pid=4217 execve guuid=8ada826b-1700-0000-deb1-e3f97d100000 pid=4221 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=8ada826b-1700-0000-deb1-e3f97d100000 pid=4221 execve guuid=5491ea6b-1700-0000-deb1-e3f97f100000 pid=4223 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=5491ea6b-1700-0000-deb1-e3f97f100000 pid=4223 execve guuid=e4464e6c-1700-0000-deb1-e3f983100000 pid=4227 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e4464e6c-1700-0000-deb1-e3f983100000 pid=4227 execve guuid=def4b06c-1700-0000-deb1-e3f986100000 pid=4230 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=def4b06c-1700-0000-deb1-e3f986100000 pid=4230 execve guuid=e48c166d-1700-0000-deb1-e3f989100000 pid=4233 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=e48c166d-1700-0000-deb1-e3f989100000 pid=4233 execve guuid=2fb67b6d-1700-0000-deb1-e3f98c100000 pid=4236 /usr/bin/ls guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=2fb67b6d-1700-0000-deb1-e3f98c100000 pid=4236 execve guuid=7845e16d-1700-0000-deb1-e3f990100000 pid=4240 /usr/bin/rm guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=7845e16d-1700-0000-deb1-e3f990100000 pid=4240 execve guuid=0e6c1b6e-1700-0000-deb1-e3f991100000 pid=4241 /usr/bin/wget net send-data write-file guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=0e6c1b6e-1700-0000-deb1-e3f991100000 pid=4241 execve guuid=71d514b2-1700-0000-deb1-e3f994110000 pid=4500 /usr/bin/chmod guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=71d514b2-1700-0000-deb1-e3f994110000 pid=4500 execve guuid=08e76db2-1700-0000-deb1-e3f995110000 pid=4501 /tmp/ojj guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=08e76db2-1700-0000-deb1-e3f995110000 pid=4501 execve guuid=625740b4-1700-0000-deb1-e3f99b110000 pid=4507 /usr/bin/rm guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=625740b4-1700-0000-deb1-e3f99b110000 pid=4507 execve guuid=52818cb4-1700-0000-deb1-e3f99f110000 pid=4511 /usr/bin/wget net send-data write-file guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=52818cb4-1700-0000-deb1-e3f99f110000 pid=4511 execve guuid=3e32d5d7-1700-0000-deb1-e3f90a120000 pid=4618 /usr/bin/chmod guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3e32d5d7-1700-0000-deb1-e3f90a120000 pid=4618 execve guuid=ae8078d8-1700-0000-deb1-e3f90b120000 pid=4619 /tmp/L4RA guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ae8078d8-1700-0000-deb1-e3f90b120000 pid=4619 execve guuid=ffbfc6d9-1700-0000-deb1-e3f90d120000 pid=4621 /usr/bin/rm guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ffbfc6d9-1700-0000-deb1-e3f90d120000 pid=4621 execve guuid=5c341fda-1700-0000-deb1-e3f90e120000 pid=4622 /usr/bin/wget net send-data write-file guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=5c341fda-1700-0000-deb1-e3f90e120000 pid=4622 execve guuid=2c1db45b-1800-0000-deb1-e3f9be130000 pid=5054 /usr/bin/chmod guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=2c1db45b-1800-0000-deb1-e3f9be130000 pid=5054 execve guuid=9743fd5b-1800-0000-deb1-e3f9bf130000 pid=5055 /tmp/fuF guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=9743fd5b-1800-0000-deb1-e3f9bf130000 pid=5055 execve guuid=814f075d-1800-0000-deb1-e3f9c4130000 pid=5060 /usr/bin/rm guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=814f075d-1800-0000-deb1-e3f9c4130000 pid=5060 execve guuid=3661515d-1800-0000-deb1-e3f9c7130000 pid=5063 /usr/bin/wget net send-data write-file guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3661515d-1800-0000-deb1-e3f9c7130000 pid=5063 execve guuid=88f9c663-1800-0000-deb1-e3f9dd130000 pid=5085 /usr/bin/chmod guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=88f9c663-1800-0000-deb1-e3f9dd130000 pid=5085 execve guuid=3f931d64-1800-0000-deb1-e3f9df130000 pid=5087 /tmp/9sI guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=3f931d64-1800-0000-deb1-e3f9df130000 pid=5087 execve guuid=ce3e0b65-1800-0000-deb1-e3f9e4130000 pid=5092 /usr/bin/rm guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=ce3e0b65-1800-0000-deb1-e3f9e4130000 pid=5092 execve guuid=7f685765-1800-0000-deb1-e3f9e5130000 pid=5093 /usr/bin/wget net send-data write-file guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=7f685765-1800-0000-deb1-e3f9e5130000 pid=5093 execve guuid=41a413a8-1800-0000-deb1-e3f91e140000 pid=5150 /usr/bin/chmod guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=41a413a8-1800-0000-deb1-e3f91e140000 pid=5150 execve guuid=f9c6a7a8-1800-0000-deb1-e3f91f140000 pid=5151 /tmp/TxJM guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=f9c6a7a8-1800-0000-deb1-e3f91f140000 pid=5151 execve guuid=8f2f25aa-1800-0000-deb1-e3f924140000 pid=5156 /usr/bin/rm delete-file guuid=d2ede03e-1700-0000-deb1-e3f9430f0000 pid=3907->guuid=8f2f25aa-1800-0000-deb1-e3f924140000 pid=5156 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=0e6c1b6e-1700-0000-deb1-e3f991100000 pid=4241->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=52818cb4-1700-0000-deb1-e3f99f110000 pid=4511->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=5c341fda-1700-0000-deb1-e3f90e120000 pid=4622->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=3661515d-1800-0000-deb1-e3f9c7130000 pid=5063->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=7f685765-1800-0000-deb1-e3f9e5130000 pid=5093->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-02 01:27:30 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8561c900bf144fcdf512eefa9cdb8c7c22b1ff4007707a242c1d3f1b332cd558

(this sample)

  
Delivery method
Distributed via web download

Comments