MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a9b58569a98930ebe0b68bddd9fb13e4ddc9e75530b283d07b853c97b6c13d8a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: a9b58569a98930ebe0b68bddd9fb13e4ddc9e75530b283d07b853c97b6c13d8a
SHA3-384 hash: daf29f386d84f8401ed7c651f51256ee773482afcfc3bd6fa56a64fb4e0e9485cc3e03f7df6361c794f4c3fb3377cbda
SHA1 hash: ba2a3ee966ebef320b85c3f14514f350c84b7675
MD5 hash: be6f4554b3eb5284b188c8ffedf32897
humanhash: asparagus-stream-lemon-muppet
File name:p
Download: download sample
File size:835 bytes
First seen:2026-06-20 21:47:43 UTC
Last seen:2026-06-21 14:10:52 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkapCrNh/jCWeCCItcfqDC1XFCyuBFUauD:kXCKysE2hi0ziQvZohapoNFPDoFi87
TLSH T158016FCA856069408129DA5D7AE7A6E0B420D3CE1A860B78BF9C193EF79C404F166F54
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/y8oNn/an/aelf ua-wget
http://129.121.114.124/DQOn/an/aelf ua-wget
http://129.121.114.124/2yrn/an/aelf ua-wget
http://129.121.114.124/DTien/an/aelf ua-wget
http://129.121.114.124/Rs9n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-20T18:54:00Z UTC
Last seen:
2026-06-21T01:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=e8a4b74e-1900-0000-6953-c1542b140000 pid=5163 /usr/bin/sudo guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164 /tmp/sample.bin write-file guuid=e8a4b74e-1900-0000-6953-c1542b140000 pid=5163->guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164 execve guuid=0c233451-1900-0000-6953-c1542d140000 pid=5165 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=0c233451-1900-0000-6953-c1542d140000 pid=5165 execve guuid=8d5b0552-1900-0000-6953-c1542e140000 pid=5166 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=8d5b0552-1900-0000-6953-c1542e140000 pid=5166 execve guuid=2cb57052-1900-0000-6953-c1542f140000 pid=5167 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=2cb57052-1900-0000-6953-c1542f140000 pid=5167 execve guuid=6e04db52-1900-0000-6953-c15430140000 pid=5168 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6e04db52-1900-0000-6953-c15430140000 pid=5168 execve guuid=21963f53-1900-0000-6953-c15431140000 pid=5169 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=21963f53-1900-0000-6953-c15431140000 pid=5169 execve guuid=a0e9a753-1900-0000-6953-c15432140000 pid=5170 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a0e9a753-1900-0000-6953-c15432140000 pid=5170 execve guuid=5fe71054-1900-0000-6953-c15433140000 pid=5171 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=5fe71054-1900-0000-6953-c15433140000 pid=5171 execve guuid=e9407454-1900-0000-6953-c15434140000 pid=5172 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=e9407454-1900-0000-6953-c15434140000 pid=5172 execve guuid=fbc4e254-1900-0000-6953-c15435140000 pid=5173 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=fbc4e254-1900-0000-6953-c15435140000 pid=5173 execve guuid=3dff5055-1900-0000-6953-c15436140000 pid=5174 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3dff5055-1900-0000-6953-c15436140000 pid=5174 execve guuid=691bba55-1900-0000-6953-c15437140000 pid=5175 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=691bba55-1900-0000-6953-c15437140000 pid=5175 execve guuid=57112356-1900-0000-6953-c15438140000 pid=5176 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=57112356-1900-0000-6953-c15438140000 pid=5176 execve guuid=51ed9356-1900-0000-6953-c15439140000 pid=5177 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=51ed9356-1900-0000-6953-c15439140000 pid=5177 execve guuid=a012ff56-1900-0000-6953-c1543a140000 pid=5178 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a012ff56-1900-0000-6953-c1543a140000 pid=5178 execve guuid=ac5f6757-1900-0000-6953-c1543b140000 pid=5179 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=ac5f6757-1900-0000-6953-c1543b140000 pid=5179 execve guuid=75d6c957-1900-0000-6953-c1543c140000 pid=5180 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=75d6c957-1900-0000-6953-c1543c140000 pid=5180 execve guuid=fb833458-1900-0000-6953-c1543d140000 pid=5181 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=fb833458-1900-0000-6953-c1543d140000 pid=5181 execve guuid=87d89b58-1900-0000-6953-c1543e140000 pid=5182 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=87d89b58-1900-0000-6953-c1543e140000 pid=5182 execve guuid=080b0559-1900-0000-6953-c1543f140000 pid=5183 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=080b0559-1900-0000-6953-c1543f140000 pid=5183 execve guuid=6b236d59-1900-0000-6953-c15440140000 pid=5184 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6b236d59-1900-0000-6953-c15440140000 pid=5184 execve guuid=9cdbd659-1900-0000-6953-c15441140000 pid=5185 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=9cdbd659-1900-0000-6953-c15441140000 pid=5185 execve guuid=c990465a-1900-0000-6953-c15442140000 pid=5186 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=c990465a-1900-0000-6953-c15442140000 pid=5186 execve guuid=adaeaa5a-1900-0000-6953-c15443140000 pid=5187 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=adaeaa5a-1900-0000-6953-c15443140000 pid=5187 execve guuid=19b1125b-1900-0000-6953-c15444140000 pid=5188 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=19b1125b-1900-0000-6953-c15444140000 pid=5188 execve guuid=8338775b-1900-0000-6953-c15445140000 pid=5189 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=8338775b-1900-0000-6953-c15445140000 pid=5189 execve guuid=9023ea5b-1900-0000-6953-c15446140000 pid=5190 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=9023ea5b-1900-0000-6953-c15446140000 pid=5190 execve guuid=203d535c-1900-0000-6953-c15447140000 pid=5191 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=203d535c-1900-0000-6953-c15447140000 pid=5191 execve guuid=5f9bc75c-1900-0000-6953-c15448140000 pid=5192 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=5f9bc75c-1900-0000-6953-c15448140000 pid=5192 execve guuid=d798435d-1900-0000-6953-c15449140000 pid=5193 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=d798435d-1900-0000-6953-c15449140000 pid=5193 execve guuid=3791bb5d-1900-0000-6953-c1544a140000 pid=5194 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3791bb5d-1900-0000-6953-c1544a140000 pid=5194 execve guuid=8ef42a5e-1900-0000-6953-c1544b140000 pid=5195 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=8ef42a5e-1900-0000-6953-c1544b140000 pid=5195 execve guuid=6620985e-1900-0000-6953-c1544c140000 pid=5196 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6620985e-1900-0000-6953-c1544c140000 pid=5196 execve guuid=af3f0d5f-1900-0000-6953-c1544d140000 pid=5197 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=af3f0d5f-1900-0000-6953-c1544d140000 pid=5197 execve guuid=90677f5f-1900-0000-6953-c1544e140000 pid=5198 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=90677f5f-1900-0000-6953-c1544e140000 pid=5198 execve guuid=5920f45f-1900-0000-6953-c1544f140000 pid=5199 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=5920f45f-1900-0000-6953-c1544f140000 pid=5199 execve guuid=7f127960-1900-0000-6953-c15450140000 pid=5200 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=7f127960-1900-0000-6953-c15450140000 pid=5200 execve guuid=600df260-1900-0000-6953-c15451140000 pid=5201 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=600df260-1900-0000-6953-c15451140000 pid=5201 execve guuid=bec36861-1900-0000-6953-c15452140000 pid=5202 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=bec36861-1900-0000-6953-c15452140000 pid=5202 execve guuid=4547ed61-1900-0000-6953-c15453140000 pid=5203 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=4547ed61-1900-0000-6953-c15453140000 pid=5203 execve guuid=6eda6862-1900-0000-6953-c15454140000 pid=5204 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6eda6862-1900-0000-6953-c15454140000 pid=5204 execve guuid=759ee862-1900-0000-6953-c15455140000 pid=5205 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=759ee862-1900-0000-6953-c15455140000 pid=5205 execve guuid=2a6c6763-1900-0000-6953-c15456140000 pid=5206 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=2a6c6763-1900-0000-6953-c15456140000 pid=5206 execve guuid=d8ade863-1900-0000-6953-c15457140000 pid=5207 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=d8ade863-1900-0000-6953-c15457140000 pid=5207 execve guuid=9ccf6864-1900-0000-6953-c15458140000 pid=5208 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=9ccf6864-1900-0000-6953-c15458140000 pid=5208 execve guuid=2590dc64-1900-0000-6953-c15459140000 pid=5209 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=2590dc64-1900-0000-6953-c15459140000 pid=5209 execve guuid=f22f6565-1900-0000-6953-c1545a140000 pid=5210 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=f22f6565-1900-0000-6953-c1545a140000 pid=5210 execve guuid=a3bce365-1900-0000-6953-c1545b140000 pid=5211 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a3bce365-1900-0000-6953-c1545b140000 pid=5211 execve guuid=26d75f66-1900-0000-6953-c1545c140000 pid=5212 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=26d75f66-1900-0000-6953-c1545c140000 pid=5212 execve guuid=42a0d466-1900-0000-6953-c1545d140000 pid=5213 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=42a0d466-1900-0000-6953-c1545d140000 pid=5213 execve guuid=66664a67-1900-0000-6953-c1545e140000 pid=5214 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=66664a67-1900-0000-6953-c1545e140000 pid=5214 execve guuid=e463b867-1900-0000-6953-c1545f140000 pid=5215 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=e463b867-1900-0000-6953-c1545f140000 pid=5215 execve guuid=435f2968-1900-0000-6953-c15460140000 pid=5216 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=435f2968-1900-0000-6953-c15460140000 pid=5216 execve guuid=9e6d9c68-1900-0000-6953-c15461140000 pid=5217 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=9e6d9c68-1900-0000-6953-c15461140000 pid=5217 execve guuid=14550c69-1900-0000-6953-c15462140000 pid=5218 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=14550c69-1900-0000-6953-c15462140000 pid=5218 execve guuid=76997869-1900-0000-6953-c15463140000 pid=5219 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=76997869-1900-0000-6953-c15463140000 pid=5219 execve guuid=c41ae969-1900-0000-6953-c15464140000 pid=5220 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=c41ae969-1900-0000-6953-c15464140000 pid=5220 execve guuid=ef6c666a-1900-0000-6953-c15465140000 pid=5221 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=ef6c666a-1900-0000-6953-c15465140000 pid=5221 execve guuid=f86ee86a-1900-0000-6953-c15466140000 pid=5222 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=f86ee86a-1900-0000-6953-c15466140000 pid=5222 execve guuid=46685e6b-1900-0000-6953-c15467140000 pid=5223 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=46685e6b-1900-0000-6953-c15467140000 pid=5223 execve guuid=11f8ca6b-1900-0000-6953-c15468140000 pid=5224 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=11f8ca6b-1900-0000-6953-c15468140000 pid=5224 execve guuid=6013576c-1900-0000-6953-c15469140000 pid=5225 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6013576c-1900-0000-6953-c15469140000 pid=5225 execve guuid=0decc66c-1900-0000-6953-c1546a140000 pid=5226 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=0decc66c-1900-0000-6953-c1546a140000 pid=5226 execve guuid=56b6306d-1900-0000-6953-c1546b140000 pid=5227 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=56b6306d-1900-0000-6953-c1546b140000 pid=5227 execve guuid=e7009d6d-1900-0000-6953-c1546c140000 pid=5228 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=e7009d6d-1900-0000-6953-c1546c140000 pid=5228 execve guuid=b694086e-1900-0000-6953-c1546d140000 pid=5229 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=b694086e-1900-0000-6953-c1546d140000 pid=5229 execve guuid=a42d766e-1900-0000-6953-c1546e140000 pid=5230 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a42d766e-1900-0000-6953-c1546e140000 pid=5230 execve guuid=0118de6e-1900-0000-6953-c1546f140000 pid=5231 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=0118de6e-1900-0000-6953-c1546f140000 pid=5231 execve guuid=5dfa4d6f-1900-0000-6953-c15470140000 pid=5232 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=5dfa4d6f-1900-0000-6953-c15470140000 pid=5232 execve guuid=7e0fb96f-1900-0000-6953-c15471140000 pid=5233 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=7e0fb96f-1900-0000-6953-c15471140000 pid=5233 execve guuid=e8172470-1900-0000-6953-c15472140000 pid=5234 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=e8172470-1900-0000-6953-c15472140000 pid=5234 execve guuid=a5678a70-1900-0000-6953-c15473140000 pid=5235 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a5678a70-1900-0000-6953-c15473140000 pid=5235 execve guuid=daecf170-1900-0000-6953-c15474140000 pid=5236 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=daecf170-1900-0000-6953-c15474140000 pid=5236 execve guuid=211a5771-1900-0000-6953-c15475140000 pid=5237 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=211a5771-1900-0000-6953-c15475140000 pid=5237 execve guuid=f06dca71-1900-0000-6953-c15476140000 pid=5238 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=f06dca71-1900-0000-6953-c15476140000 pid=5238 execve guuid=d80c4372-1900-0000-6953-c15477140000 pid=5239 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=d80c4372-1900-0000-6953-c15477140000 pid=5239 execve guuid=70c8b472-1900-0000-6953-c15478140000 pid=5240 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=70c8b472-1900-0000-6953-c15478140000 pid=5240 execve guuid=6ae42b73-1900-0000-6953-c15479140000 pid=5241 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6ae42b73-1900-0000-6953-c15479140000 pid=5241 execve guuid=13bb9a73-1900-0000-6953-c1547a140000 pid=5242 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=13bb9a73-1900-0000-6953-c1547a140000 pid=5242 execve guuid=37431274-1900-0000-6953-c1547b140000 pid=5243 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=37431274-1900-0000-6953-c1547b140000 pid=5243 execve guuid=66c78474-1900-0000-6953-c1547c140000 pid=5244 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=66c78474-1900-0000-6953-c1547c140000 pid=5244 execve guuid=60ddf474-1900-0000-6953-c1547d140000 pid=5245 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=60ddf474-1900-0000-6953-c1547d140000 pid=5245 execve guuid=588a5e75-1900-0000-6953-c1547e140000 pid=5246 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=588a5e75-1900-0000-6953-c1547e140000 pid=5246 execve guuid=d696c875-1900-0000-6953-c1547f140000 pid=5247 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=d696c875-1900-0000-6953-c1547f140000 pid=5247 execve guuid=6aa43276-1900-0000-6953-c15480140000 pid=5248 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6aa43276-1900-0000-6953-c15480140000 pid=5248 execve guuid=23ae9876-1900-0000-6953-c15481140000 pid=5249 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=23ae9876-1900-0000-6953-c15481140000 pid=5249 execve guuid=74fc0177-1900-0000-6953-c15482140000 pid=5250 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=74fc0177-1900-0000-6953-c15482140000 pid=5250 execve guuid=45d26d77-1900-0000-6953-c15483140000 pid=5251 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=45d26d77-1900-0000-6953-c15483140000 pid=5251 execve guuid=76cbd577-1900-0000-6953-c15484140000 pid=5252 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=76cbd577-1900-0000-6953-c15484140000 pid=5252 execve guuid=319a4278-1900-0000-6953-c15485140000 pid=5253 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=319a4278-1900-0000-6953-c15485140000 pid=5253 execve guuid=207daf78-1900-0000-6953-c15486140000 pid=5254 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=207daf78-1900-0000-6953-c15486140000 pid=5254 execve guuid=37b22379-1900-0000-6953-c15487140000 pid=5255 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=37b22379-1900-0000-6953-c15487140000 pid=5255 execve guuid=45e99279-1900-0000-6953-c15488140000 pid=5256 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=45e99279-1900-0000-6953-c15488140000 pid=5256 execve guuid=9431047a-1900-0000-6953-c15489140000 pid=5257 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=9431047a-1900-0000-6953-c15489140000 pid=5257 execve guuid=3d15707a-1900-0000-6953-c1548a140000 pid=5258 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3d15707a-1900-0000-6953-c1548a140000 pid=5258 execve guuid=ea58d97a-1900-0000-6953-c1548b140000 pid=5259 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=ea58d97a-1900-0000-6953-c1548b140000 pid=5259 execve guuid=70b3497b-1900-0000-6953-c1548c140000 pid=5260 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=70b3497b-1900-0000-6953-c1548c140000 pid=5260 execve guuid=bc7fb97b-1900-0000-6953-c1548d140000 pid=5261 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=bc7fb97b-1900-0000-6953-c1548d140000 pid=5261 execve guuid=3d41287c-1900-0000-6953-c1548e140000 pid=5262 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3d41287c-1900-0000-6953-c1548e140000 pid=5262 execve guuid=8efb9c7c-1900-0000-6953-c1548f140000 pid=5263 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=8efb9c7c-1900-0000-6953-c1548f140000 pid=5263 execve guuid=c4e0007d-1900-0000-6953-c15490140000 pid=5264 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=c4e0007d-1900-0000-6953-c15490140000 pid=5264 execve guuid=c55e647d-1900-0000-6953-c15491140000 pid=5265 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=c55e647d-1900-0000-6953-c15491140000 pid=5265 execve guuid=aa2fe87d-1900-0000-6953-c15492140000 pid=5266 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=aa2fe87d-1900-0000-6953-c15492140000 pid=5266 execve guuid=19e4457e-1900-0000-6953-c15493140000 pid=5267 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=19e4457e-1900-0000-6953-c15493140000 pid=5267 execve guuid=3f9aa87e-1900-0000-6953-c15494140000 pid=5268 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3f9aa87e-1900-0000-6953-c15494140000 pid=5268 execve guuid=f9421c7f-1900-0000-6953-c15495140000 pid=5269 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=f9421c7f-1900-0000-6953-c15495140000 pid=5269 execve guuid=c700847f-1900-0000-6953-c15496140000 pid=5270 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=c700847f-1900-0000-6953-c15496140000 pid=5270 execve guuid=7ff5f57f-1900-0000-6953-c15497140000 pid=5271 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=7ff5f57f-1900-0000-6953-c15497140000 pid=5271 execve guuid=db295680-1900-0000-6953-c15498140000 pid=5272 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=db295680-1900-0000-6953-c15498140000 pid=5272 execve guuid=8453ca80-1900-0000-6953-c15499140000 pid=5273 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=8453ca80-1900-0000-6953-c15499140000 pid=5273 execve guuid=3bfe4181-1900-0000-6953-c1549a140000 pid=5274 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3bfe4181-1900-0000-6953-c1549a140000 pid=5274 execve guuid=6a2cb481-1900-0000-6953-c1549b140000 pid=5275 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6a2cb481-1900-0000-6953-c1549b140000 pid=5275 execve guuid=ee312882-1900-0000-6953-c1549c140000 pid=5276 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=ee312882-1900-0000-6953-c1549c140000 pid=5276 execve guuid=08949b82-1900-0000-6953-c1549d140000 pid=5277 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=08949b82-1900-0000-6953-c1549d140000 pid=5277 execve guuid=71ccff82-1900-0000-6953-c1549e140000 pid=5278 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=71ccff82-1900-0000-6953-c1549e140000 pid=5278 execve guuid=d48b6d83-1900-0000-6953-c1549f140000 pid=5279 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=d48b6d83-1900-0000-6953-c1549f140000 pid=5279 execve guuid=ba9adf83-1900-0000-6953-c154a0140000 pid=5280 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=ba9adf83-1900-0000-6953-c154a0140000 pid=5280 execve guuid=1f734b84-1900-0000-6953-c154a1140000 pid=5281 /usr/bin/ls guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=1f734b84-1900-0000-6953-c154a1140000 pid=5281 execve guuid=a147b884-1900-0000-6953-c154a2140000 pid=5282 /usr/bin/rm guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a147b884-1900-0000-6953-c154a2140000 pid=5282 execve guuid=a89dfc84-1900-0000-6953-c154a3140000 pid=5283 /usr/bin/wget net send-data write-file guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=a89dfc84-1900-0000-6953-c154a3140000 pid=5283 execve guuid=2dd5ad9e-1900-0000-6953-c154a4140000 pid=5284 /usr/bin/chmod guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=2dd5ad9e-1900-0000-6953-c154a4140000 pid=5284 execve guuid=11abf89e-1900-0000-6953-c154a5140000 pid=5285 /usr/bin/dash guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=11abf89e-1900-0000-6953-c154a5140000 pid=5285 clone guuid=3f6acda0-1900-0000-6953-c154a7140000 pid=5287 /usr/bin/rm guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=3f6acda0-1900-0000-6953-c154a7140000 pid=5287 execve guuid=91440da1-1900-0000-6953-c154a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=91440da1-1900-0000-6953-c154a8140000 pid=5288 execve guuid=785ecfbb-1900-0000-6953-c154a9140000 pid=5289 /usr/bin/chmod guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=785ecfbb-1900-0000-6953-c154a9140000 pid=5289 execve guuid=2bb51dbc-1900-0000-6953-c154aa140000 pid=5290 /usr/bin/dash guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=2bb51dbc-1900-0000-6953-c154aa140000 pid=5290 clone guuid=6531c2bc-1900-0000-6953-c154ac140000 pid=5292 /usr/bin/rm guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6531c2bc-1900-0000-6953-c154ac140000 pid=5292 execve guuid=cad015bd-1900-0000-6953-c154ad140000 pid=5293 /usr/bin/wget net send-data write-file guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=cad015bd-1900-0000-6953-c154ad140000 pid=5293 execve guuid=8a3898d5-1900-0000-6953-c154ae140000 pid=5294 /usr/bin/chmod guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=8a3898d5-1900-0000-6953-c154ae140000 pid=5294 execve guuid=5b1b41d6-1900-0000-6953-c154af140000 pid=5295 /usr/bin/dash guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=5b1b41d6-1900-0000-6953-c154af140000 pid=5295 clone guuid=f1ed4dd8-1900-0000-6953-c154b1140000 pid=5297 /usr/bin/rm guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=f1ed4dd8-1900-0000-6953-c154b1140000 pid=5297 execve guuid=d4d590d8-1900-0000-6953-c154b2140000 pid=5298 /usr/bin/wget net send-data write-file guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=d4d590d8-1900-0000-6953-c154b2140000 pid=5298 execve guuid=1f0e1ff5-1900-0000-6953-c154ba140000 pid=5306 /usr/bin/chmod guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=1f0e1ff5-1900-0000-6953-c154ba140000 pid=5306 execve guuid=01b27bf5-1900-0000-6953-c154bb140000 pid=5307 /usr/bin/dash guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=01b27bf5-1900-0000-6953-c154bb140000 pid=5307 clone guuid=abf740f6-1900-0000-6953-c154bd140000 pid=5309 /usr/bin/rm guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=abf740f6-1900-0000-6953-c154bd140000 pid=5309 execve guuid=6dc296f6-1900-0000-6953-c154be140000 pid=5310 /usr/bin/wget net send-data write-file guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=6dc296f6-1900-0000-6953-c154be140000 pid=5310 execve guuid=cd302b13-1a00-0000-6953-c154bf140000 pid=5311 /usr/bin/chmod guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=cd302b13-1a00-0000-6953-c154bf140000 pid=5311 execve guuid=0797d513-1a00-0000-6953-c154c0140000 pid=5312 /usr/bin/dash guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=0797d513-1a00-0000-6953-c154c0140000 pid=5312 clone guuid=2a2ffa2e-1a00-0000-6953-c154c2140000 pid=5314 /usr/bin/rm delete-file guuid=769ae250-1900-0000-6953-c1542c140000 pid=5164->guuid=2a2ffa2e-1a00-0000-6953-c154c2140000 pid=5314 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=a89dfc84-1900-0000-6953-c154a3140000 pid=5283->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=91440da1-1900-0000-6953-c154a8140000 pid=5288->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=cad015bd-1900-0000-6953-c154ad140000 pid=5293->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=d4d590d8-1900-0000-6953-c154b2140000 pid=5298->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=6dc296f6-1900-0000-6953-c154be140000 pid=5310->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-20 21:48:24 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a9b58569a98930ebe0b68bddd9fb13e4ddc9e75530b283d07b853c97b6c13d8a

(this sample)

  
Delivery method
Distributed via web download

Comments