MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 86cb8249ca6048013d76543c3dae4a16b0519dc96491de344fdf363ab05bb623. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 86cb8249ca6048013d76543c3dae4a16b0519dc96491de344fdf363ab05bb623
SHA3-384 hash: c219d9e2ebff9896a8325e0ab7ca3798d62e9d27471356ac033da45c2cd2a4ae0555e4617a759b87c29d48efed79ecf8
SHA1 hash: f7661d319a76db7a65eba2be32531c9b2ffa3f8a
MD5 hash: 3c931b0372a3ce0d8125e5d8bb425224
humanhash: ink-vermont-oxygen-twelve
File name:bins.sh
Download: download sample
File size:523 bytes
First seen:2025-06-28 08:53:41 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:lOnFflE0FLeQQiMxFeQQiMBviMuiMTALQZcbnMAMQrAgsLQN6PcbZusQLQ55D5M6:v0F8+ZTNnrkM2B4D5N7Q5q
TLSH T196F0B4C82525303927C39A0F136388D4F364C098E8234EF88DCCF9D1A894CA1242CABD
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.90/0x83911d24Fx.shn/an/ash ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader trojan agent
Status:
terminated
Behavior Graph:
%3 guuid=fbb7670b-1900-0000-532a-87626d0f0000 pid=3949 /usr/bin/sudo guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956 /tmp/sample.bin guuid=fbb7670b-1900-0000-532a-87626d0f0000 pid=3949->guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956 execve guuid=ec2d380d-1900-0000-532a-8762750f0000 pid=3957 /usr/bin/wget net send-data write-file guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=ec2d380d-1900-0000-532a-8762750f0000 pid=3957 execve guuid=92d1a217-1900-0000-532a-87629b0f0000 pid=3995 /usr/bin/curl net send-data write-file guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=92d1a217-1900-0000-532a-87629b0f0000 pid=3995 execve guuid=aa822624-1900-0000-532a-8762c70f0000 pid=4039 /usr/bin/chmod guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=aa822624-1900-0000-532a-8762c70f0000 pid=4039 execve guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042 /usr/bin/dash guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042 execve guuid=d79f0514-1a00-0000-532a-876250130000 pid=4944 /usr/bin/chmod guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=d79f0514-1a00-0000-532a-876250130000 pid=4944 execve guuid=f84c8714-1a00-0000-532a-876253130000 pid=4947 /usr/bin/dash guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=f84c8714-1a00-0000-532a-876253130000 pid=4947 execve guuid=22e6dd14-1a00-0000-532a-876255130000 pid=4949 /usr/bin/chmod guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=22e6dd14-1a00-0000-532a-876255130000 pid=4949 execve guuid=13078c15-1a00-0000-532a-876258130000 pid=4952 /usr/bin/dash guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=13078c15-1a00-0000-532a-876258130000 pid=4952 execve guuid=6f0de915-1a00-0000-532a-87625a130000 pid=4954 /usr/bin/dash guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=6f0de915-1a00-0000-532a-87625a130000 pid=4954 execve guuid=8ab72c16-1a00-0000-532a-87625b130000 pid=4955 /usr/bin/rm guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=8ab72c16-1a00-0000-532a-87625b130000 pid=4955 execve guuid=7c40a516-1a00-0000-532a-87625e130000 pid=4958 /usr/bin/rm delete-file guuid=95b3030d-1900-0000-532a-8762740f0000 pid=3956->guuid=7c40a516-1a00-0000-532a-87625e130000 pid=4958 execve d4397235-db59-5ea7-bbe2-8e3d89efa460 45.125.66.90:80 guuid=ec2d380d-1900-0000-532a-8762750f0000 pid=3957->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=92d1a217-1900-0000-532a-87629b0f0000 pid=3995->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=93d2cb24-1900-0000-532a-8762cb0f0000 pid=4043 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=93d2cb24-1900-0000-532a-8762cb0f0000 pid=4043 execve guuid=607c082c-1900-0000-532a-8762eb0f0000 pid=4075 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=607c082c-1900-0000-532a-8762eb0f0000 pid=4075 execve guuid=13c48c34-1900-0000-532a-87620b100000 pid=4107 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=13c48c34-1900-0000-532a-87620b100000 pid=4107 execve guuid=18b1cb34-1900-0000-532a-87620d100000 pid=4109 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=18b1cb34-1900-0000-532a-87620d100000 pid=4109 execve guuid=49380935-1900-0000-532a-87620e100000 pid=4110 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=49380935-1900-0000-532a-87620e100000 pid=4110 execve guuid=5e283c35-1900-0000-532a-876210100000 pid=4112 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=5e283c35-1900-0000-532a-876210100000 pid=4112 execve guuid=6dff5740-1900-0000-532a-87623a100000 pid=4154 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=6dff5740-1900-0000-532a-87623a100000 pid=4154 execve guuid=02224a49-1900-0000-532a-87624d100000 pid=4173 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=02224a49-1900-0000-532a-87624d100000 pid=4173 execve guuid=01d4c349-1900-0000-532a-87624f100000 pid=4175 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=01d4c349-1900-0000-532a-87624f100000 pid=4175 execve guuid=346e244a-1900-0000-532a-876251100000 pid=4177 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=346e244a-1900-0000-532a-876251100000 pid=4177 execve guuid=4f5d724a-1900-0000-532a-876253100000 pid=4179 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=4f5d724a-1900-0000-532a-876253100000 pid=4179 execve guuid=6ffc3e55-1900-0000-532a-87627d100000 pid=4221 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=6ffc3e55-1900-0000-532a-87627d100000 pid=4221 execve guuid=1364925f-1900-0000-532a-8762b2100000 pid=4274 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=1364925f-1900-0000-532a-8762b2100000 pid=4274 execve guuid=79efe65f-1900-0000-532a-8762b4100000 pid=4276 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=79efe65f-1900-0000-532a-8762b4100000 pid=4276 execve guuid=22dc4060-1900-0000-532a-8762b6100000 pid=4278 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=22dc4060-1900-0000-532a-8762b6100000 pid=4278 execve guuid=c0d08f60-1900-0000-532a-8762b8100000 pid=4280 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=c0d08f60-1900-0000-532a-8762b8100000 pid=4280 execve guuid=2188ae67-1900-0000-532a-8762cf100000 pid=4303 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=2188ae67-1900-0000-532a-8762cf100000 pid=4303 execve guuid=dd985471-1900-0000-532a-8762f2100000 pid=4338 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=dd985471-1900-0000-532a-8762f2100000 pid=4338 execve guuid=5fcd9271-1900-0000-532a-8762f3100000 pid=4339 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=5fcd9271-1900-0000-532a-8762f3100000 pid=4339 execve guuid=fcd3c971-1900-0000-532a-8762f7100000 pid=4343 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=fcd3c971-1900-0000-532a-8762f7100000 pid=4343 execve guuid=7758fc71-1900-0000-532a-8762f8100000 pid=4344 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=7758fc71-1900-0000-532a-8762f8100000 pid=4344 execve guuid=2477db78-1900-0000-532a-876217110000 pid=4375 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=2477db78-1900-0000-532a-876217110000 pid=4375 execve guuid=d7439a82-1900-0000-532a-876241110000 pid=4417 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=d7439a82-1900-0000-532a-876241110000 pid=4417 execve guuid=08ccd782-1900-0000-532a-876243110000 pid=4419 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=08ccd782-1900-0000-532a-876243110000 pid=4419 execve guuid=7cb11183-1900-0000-532a-876245110000 pid=4421 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=7cb11183-1900-0000-532a-876245110000 pid=4421 execve guuid=18404383-1900-0000-532a-876246110000 pid=4422 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=18404383-1900-0000-532a-876246110000 pid=4422 execve guuid=36605a8a-1900-0000-532a-87626c110000 pid=4460 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=36605a8a-1900-0000-532a-87626c110000 pid=4460 execve guuid=87113e92-1900-0000-532a-87628e110000 pid=4494 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=87113e92-1900-0000-532a-87628e110000 pid=4494 execve guuid=f6a49f92-1900-0000-532a-876290110000 pid=4496 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=f6a49f92-1900-0000-532a-876290110000 pid=4496 execve guuid=c4ddf092-1900-0000-532a-876292110000 pid=4498 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=c4ddf092-1900-0000-532a-876292110000 pid=4498 execve guuid=f16a3693-1900-0000-532a-876295110000 pid=4501 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=f16a3693-1900-0000-532a-876295110000 pid=4501 execve guuid=b427419a-1900-0000-532a-8762a8110000 pid=4520 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=b427419a-1900-0000-532a-8762a8110000 pid=4520 execve guuid=d33382a2-1900-0000-532a-8762b8110000 pid=4536 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=d33382a2-1900-0000-532a-8762b8110000 pid=4536 execve guuid=f72806a3-1900-0000-532a-8762bd110000 pid=4541 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=f72806a3-1900-0000-532a-8762bd110000 pid=4541 execve guuid=f4e84da3-1900-0000-532a-8762be110000 pid=4542 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=f4e84da3-1900-0000-532a-8762be110000 pid=4542 execve guuid=5a6b84a3-1900-0000-532a-8762bf110000 pid=4543 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=5a6b84a3-1900-0000-532a-8762bf110000 pid=4543 execve guuid=d2faa1aa-1900-0000-532a-8762e6110000 pid=4582 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=d2faa1aa-1900-0000-532a-8762e6110000 pid=4582 execve guuid=77be53b3-1900-0000-532a-876214120000 pid=4628 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=77be53b3-1900-0000-532a-876214120000 pid=4628 execve guuid=9aa58cb3-1900-0000-532a-876218120000 pid=4632 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=9aa58cb3-1900-0000-532a-876218120000 pid=4632 execve guuid=a89dc2b3-1900-0000-532a-876219120000 pid=4633 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=a89dc2b3-1900-0000-532a-876219120000 pid=4633 execve guuid=e8b6f0b3-1900-0000-532a-87621b120000 pid=4635 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=e8b6f0b3-1900-0000-532a-87621b120000 pid=4635 execve guuid=19e272be-1900-0000-532a-87623a120000 pid=4666 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=19e272be-1900-0000-532a-87623a120000 pid=4666 execve guuid=d3505fc8-1900-0000-532a-876264120000 pid=4708 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=d3505fc8-1900-0000-532a-876264120000 pid=4708 execve guuid=291dc7c8-1900-0000-532a-876266120000 pid=4710 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=291dc7c8-1900-0000-532a-876266120000 pid=4710 execve guuid=95602dc9-1900-0000-532a-876268120000 pid=4712 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=95602dc9-1900-0000-532a-876268120000 pid=4712 execve guuid=7aa17fc9-1900-0000-532a-87626c120000 pid=4716 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=7aa17fc9-1900-0000-532a-87626c120000 pid=4716 execve guuid=c238e4d0-1900-0000-532a-876287120000 pid=4743 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=c238e4d0-1900-0000-532a-876287120000 pid=4743 execve guuid=f867f6d8-1900-0000-532a-8762a0120000 pid=4768 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=f867f6d8-1900-0000-532a-8762a0120000 pid=4768 execve guuid=941459d9-1900-0000-532a-8762a1120000 pid=4769 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=941459d9-1900-0000-532a-8762a1120000 pid=4769 execve guuid=ec59e5d9-1900-0000-532a-8762a4120000 pid=4772 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=ec59e5d9-1900-0000-532a-8762a4120000 pid=4772 execve guuid=5fa526da-1900-0000-532a-8762a5120000 pid=4773 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=5fa526da-1900-0000-532a-8762a5120000 pid=4773 execve guuid=473aefe5-1900-0000-532a-8762bb120000 pid=4795 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=473aefe5-1900-0000-532a-8762bb120000 pid=4795 execve guuid=0c756df0-1900-0000-532a-8762dd120000 pid=4829 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=0c756df0-1900-0000-532a-8762dd120000 pid=4829 execve guuid=031c14f1-1900-0000-532a-8762df120000 pid=4831 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=031c14f1-1900-0000-532a-8762df120000 pid=4831 execve guuid=66dbf8f1-1900-0000-532a-8762e3120000 pid=4835 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=66dbf8f1-1900-0000-532a-8762e3120000 pid=4835 execve guuid=6a8494f2-1900-0000-532a-8762e7120000 pid=4839 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=6a8494f2-1900-0000-532a-8762e7120000 pid=4839 execve guuid=db6518fa-1900-0000-532a-8762fc120000 pid=4860 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=db6518fa-1900-0000-532a-8762fc120000 pid=4860 execve guuid=98460302-1a00-0000-532a-876214130000 pid=4884 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=98460302-1a00-0000-532a-876214130000 pid=4884 execve guuid=ee7d5f02-1a00-0000-532a-876216130000 pid=4886 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=ee7d5f02-1a00-0000-532a-876216130000 pid=4886 execve guuid=bcbab402-1a00-0000-532a-876218130000 pid=4888 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=bcbab402-1a00-0000-532a-876218130000 pid=4888 execve guuid=cbe3f502-1a00-0000-532a-87621a130000 pid=4890 /usr/bin/wget net send-data guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=cbe3f502-1a00-0000-532a-87621a130000 pid=4890 execve guuid=ca75610a-1a00-0000-532a-876230130000 pid=4912 /usr/bin/curl net send-data write-file guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=ca75610a-1a00-0000-532a-876230130000 pid=4912 execve guuid=1cf62f13-1a00-0000-532a-87624b130000 pid=4939 /usr/bin/cat guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=1cf62f13-1a00-0000-532a-87624b130000 pid=4939 execve guuid=df1d7913-1a00-0000-532a-87624c130000 pid=4940 /usr/bin/chmod guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=df1d7913-1a00-0000-532a-87624c130000 pid=4940 execve guuid=0524c613-1a00-0000-532a-87624e130000 pid=4942 /tmp/x guuid=6e649124-1900-0000-532a-8762ca0f0000 pid=4042->guuid=0524c613-1a00-0000-532a-87624e130000 pid=4942 execve guuid=93d2cb24-1900-0000-532a-8762cb0f0000 pid=4043->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=607c082c-1900-0000-532a-8762eb0f0000 pid=4075->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=5e283c35-1900-0000-532a-876210100000 pid=4112->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 143B guuid=6dff5740-1900-0000-532a-87623a100000 pid=4154->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 92B guuid=4f5d724a-1900-0000-532a-876253100000 pid=4179->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 143B guuid=6ffc3e55-1900-0000-532a-87627d100000 pid=4221->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 92B guuid=c0d08f60-1900-0000-532a-8762b8100000 pid=4280->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=2188ae67-1900-0000-532a-8762cf100000 pid=4303->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=7758fc71-1900-0000-532a-8762f8100000 pid=4344->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 143B guuid=2477db78-1900-0000-532a-876217110000 pid=4375->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 92B guuid=18404383-1900-0000-532a-876246110000 pid=4422->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 143B guuid=36605a8a-1900-0000-532a-87626c110000 pid=4460->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 92B guuid=f16a3693-1900-0000-532a-876295110000 pid=4501->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 143B guuid=b427419a-1900-0000-532a-8762a8110000 pid=4520->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 92B guuid=5a6b84a3-1900-0000-532a-8762bf110000 pid=4543->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=d2faa1aa-1900-0000-532a-8762e6110000 pid=4582->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=e8b6f0b3-1900-0000-532a-87621b120000 pid=4635->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 143B guuid=19e272be-1900-0000-532a-87623a120000 pid=4666->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 92B guuid=7aa17fc9-1900-0000-532a-87626c120000 pid=4716->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=c238e4d0-1900-0000-532a-876287120000 pid=4743->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=5fa526da-1900-0000-532a-8762a5120000 pid=4773->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=473aefe5-1900-0000-532a-8762bb120000 pid=4795->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=6a8494f2-1900-0000-532a-8762e7120000 pid=4839->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 142B guuid=db6518fa-1900-0000-532a-8762fc120000 pid=4860->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 91B guuid=cbe3f502-1a00-0000-532a-87621a130000 pid=4890->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 145B guuid=ca75610a-1a00-0000-532a-876230130000 pid=4912->d4397235-db59-5ea7-bbe2-8e3d89efa460 send: 94B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-28 08:54:27 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 86cb8249ca6048013d76543c3dae4a16b0519dc96491de344fdf363ab05bb623

(this sample)

  
Delivery method
Distributed via web download

Comments