MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abb381c26520d856f9d7f8ea742675c12c49fb95fbbd325007783153fcc2a617. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: abb381c26520d856f9d7f8ea742675c12c49fb95fbbd325007783153fcc2a617
SHA3-384 hash: f595e47acee3f536367566e5b5b9380f67ea9793e97714a9f40dc4779bea9790361b812092223efb148b6daf8626e0e1
SHA1 hash: 1902896117af024672c4e473199cd51620c39605
MD5 hash: bc885a0ea101489f73e49f4cd771ae33
humanhash: mockingbird-ten-dakota-montana
File name:ok
Download: download sample
File size:1'608 bytes
First seen:2026-06-08 13:53:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:5QrWdfua+IirI4KU2/rVaYryQvrQNZ1YQrL/bCr9CeWA7rWsrcYrrFJDCY9AFr9X:5dfuMXDU2rnsDfA2yPDRmmMg/Y
TLSH T13731C99B0B193B984424EAA773B01958D564F5DE209FD7A0FF880C7A92C8549330DB4F
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/7afd8fn/an/aelf ua-wget
http://45.205.1.59/297a79n/an/aelf ua-wget
http://45.205.1.59/2d6571n/an/aelf ua-wget
http://45.205.1.59/d4a14fn/an/aelf ua-wget
http://45.205.1.59/16466an/an/aelf ua-wget
http://45.205.1.59/a8611en/an/aelf ua-wget
http://45.205.1.59/544196n/an/aelf ua-wget
http://45.205.1.59/35754fn/an/aelf ua-wget
http://45.205.1.59/e1502en/an/aelf ua-wget
http://45.205.1.59/64afa1n/an/aelf ua-wget
http://45.205.1.59/e0a338n/an/aelf ua-wget
http://45.205.1.59/5a1b70n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=7104b9fb-1a00-0000-fe8f-5f119b0a0000 pid=2715 /usr/bin/sudo guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720 /tmp/sample.bin guuid=7104b9fb-1a00-0000-fe8f-5f119b0a0000 pid=2715->guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720 execve guuid=190086fe-1a00-0000-fe8f-5f11a40a0000 pid=2724 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=190086fe-1a00-0000-fe8f-5f11a40a0000 pid=2724 execve guuid=7ab9d31b-1b00-0000-fe8f-5f11d30a0000 pid=2771 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=7ab9d31b-1b00-0000-fe8f-5f11d30a0000 pid=2771 execve guuid=9941313e-1b00-0000-fe8f-5f11060b0000 pid=2822 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=9941313e-1b00-0000-fe8f-5f11060b0000 pid=2822 execve guuid=cd937d3e-1b00-0000-fe8f-5f11080b0000 pid=2824 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=cd937d3e-1b00-0000-fe8f-5f11080b0000 pid=2824 clone guuid=46face3e-1b00-0000-fe8f-5f110b0b0000 pid=2827 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=46face3e-1b00-0000-fe8f-5f110b0b0000 pid=2827 execve guuid=4c391f3f-1b00-0000-fe8f-5f110c0b0000 pid=2828 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=4c391f3f-1b00-0000-fe8f-5f110c0b0000 pid=2828 execve guuid=23976d3f-1b00-0000-fe8f-5f110e0b0000 pid=2830 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=23976d3f-1b00-0000-fe8f-5f110e0b0000 pid=2830 execve guuid=39a1ea5a-1b00-0000-fe8f-5f114a0b0000 pid=2890 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=39a1ea5a-1b00-0000-fe8f-5f114a0b0000 pid=2890 execve guuid=51cc3f7b-1b00-0000-fe8f-5f11820b0000 pid=2946 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=51cc3f7b-1b00-0000-fe8f-5f11820b0000 pid=2946 execve guuid=24b8a07b-1b00-0000-fe8f-5f11830b0000 pid=2947 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=24b8a07b-1b00-0000-fe8f-5f11830b0000 pid=2947 clone guuid=51ebda7b-1b00-0000-fe8f-5f11860b0000 pid=2950 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=51ebda7b-1b00-0000-fe8f-5f11860b0000 pid=2950 execve guuid=d1bb517c-1b00-0000-fe8f-5f11870b0000 pid=2951 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=d1bb517c-1b00-0000-fe8f-5f11870b0000 pid=2951 execve guuid=98d4ef7c-1b00-0000-fe8f-5f11880b0000 pid=2952 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=98d4ef7c-1b00-0000-fe8f-5f11880b0000 pid=2952 execve guuid=2beee798-1b00-0000-fe8f-5f11bd0b0000 pid=3005 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=2beee798-1b00-0000-fe8f-5f11bd0b0000 pid=3005 execve guuid=c8096db7-1b00-0000-fe8f-5f11f90b0000 pid=3065 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=c8096db7-1b00-0000-fe8f-5f11f90b0000 pid=3065 execve guuid=206c2bb8-1b00-0000-fe8f-5f11fb0b0000 pid=3067 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=206c2bb8-1b00-0000-fe8f-5f11fb0b0000 pid=3067 clone guuid=b398a9b8-1b00-0000-fe8f-5f11fe0b0000 pid=3070 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=b398a9b8-1b00-0000-fe8f-5f11fe0b0000 pid=3070 execve guuid=0ab33eb9-1b00-0000-fe8f-5f11ff0b0000 pid=3071 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=0ab33eb9-1b00-0000-fe8f-5f11ff0b0000 pid=3071 execve guuid=af68a7b9-1b00-0000-fe8f-5f11010c0000 pid=3073 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=af68a7b9-1b00-0000-fe8f-5f11010c0000 pid=3073 execve guuid=4eee32d6-1b00-0000-fe8f-5f11390c0000 pid=3129 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=4eee32d6-1b00-0000-fe8f-5f11390c0000 pid=3129 execve guuid=ad44e7f4-1b00-0000-fe8f-5f11780c0000 pid=3192 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=ad44e7f4-1b00-0000-fe8f-5f11780c0000 pid=3192 execve guuid=362d45f5-1b00-0000-fe8f-5f117a0c0000 pid=3194 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=362d45f5-1b00-0000-fe8f-5f117a0c0000 pid=3194 clone guuid=fda07ff5-1b00-0000-fe8f-5f117d0c0000 pid=3197 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=fda07ff5-1b00-0000-fe8f-5f117d0c0000 pid=3197 execve guuid=dc59e5f5-1b00-0000-fe8f-5f117e0c0000 pid=3198 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=dc59e5f5-1b00-0000-fe8f-5f117e0c0000 pid=3198 execve guuid=e7264bf6-1b00-0000-fe8f-5f11810c0000 pid=3201 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=e7264bf6-1b00-0000-fe8f-5f11810c0000 pid=3201 execve guuid=57f05f12-1c00-0000-fe8f-5f11a60c0000 pid=3238 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=57f05f12-1c00-0000-fe8f-5f11a60c0000 pid=3238 execve guuid=9a38c22f-1c00-0000-fe8f-5f11c40c0000 pid=3268 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=9a38c22f-1c00-0000-fe8f-5f11c40c0000 pid=3268 execve guuid=04da5330-1c00-0000-fe8f-5f11c50c0000 pid=3269 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=04da5330-1c00-0000-fe8f-5f11c50c0000 pid=3269 clone guuid=d355bc30-1c00-0000-fe8f-5f11c80c0000 pid=3272 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=d355bc30-1c00-0000-fe8f-5f11c80c0000 pid=3272 execve guuid=883b3f31-1c00-0000-fe8f-5f11ca0c0000 pid=3274 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=883b3f31-1c00-0000-fe8f-5f11ca0c0000 pid=3274 execve guuid=5bd6ba31-1c00-0000-fe8f-5f11cc0c0000 pid=3276 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=5bd6ba31-1c00-0000-fe8f-5f11cc0c0000 pid=3276 execve guuid=56db134f-1c00-0000-fe8f-5f11f80c0000 pid=3320 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=56db134f-1c00-0000-fe8f-5f11f80c0000 pid=3320 execve guuid=b5d8e06d-1c00-0000-fe8f-5f111f0d0000 pid=3359 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=b5d8e06d-1c00-0000-fe8f-5f111f0d0000 pid=3359 execve guuid=2488926e-1c00-0000-fe8f-5f11200d0000 pid=3360 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=2488926e-1c00-0000-fe8f-5f11200d0000 pid=3360 clone guuid=242e526f-1c00-0000-fe8f-5f11220d0000 pid=3362 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=242e526f-1c00-0000-fe8f-5f11220d0000 pid=3362 execve guuid=3c8bc86f-1c00-0000-fe8f-5f11230d0000 pid=3363 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=3c8bc86f-1c00-0000-fe8f-5f11230d0000 pid=3363 execve guuid=058f2c70-1c00-0000-fe8f-5f11240d0000 pid=3364 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=058f2c70-1c00-0000-fe8f-5f11240d0000 pid=3364 execve guuid=27a4e08b-1c00-0000-fe8f-5f114f0d0000 pid=3407 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=27a4e08b-1c00-0000-fe8f-5f114f0d0000 pid=3407 execve guuid=59e7e5aa-1c00-0000-fe8f-5f11990d0000 pid=3481 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=59e7e5aa-1c00-0000-fe8f-5f11990d0000 pid=3481 execve guuid=191942ab-1c00-0000-fe8f-5f119b0d0000 pid=3483 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=191942ab-1c00-0000-fe8f-5f119b0d0000 pid=3483 clone guuid=77118dab-1c00-0000-fe8f-5f119e0d0000 pid=3486 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=77118dab-1c00-0000-fe8f-5f119e0d0000 pid=3486 execve guuid=782ef8ab-1c00-0000-fe8f-5f119f0d0000 pid=3487 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=782ef8ab-1c00-0000-fe8f-5f119f0d0000 pid=3487 execve guuid=c0ab4eac-1c00-0000-fe8f-5f11a20d0000 pid=3490 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=c0ab4eac-1c00-0000-fe8f-5f11a20d0000 pid=3490 execve guuid=310172c8-1c00-0000-fe8f-5f11dc0d0000 pid=3548 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=310172c8-1c00-0000-fe8f-5f11dc0d0000 pid=3548 execve guuid=e91eece5-1c00-0000-fe8f-5f110a0e0000 pid=3594 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=e91eece5-1c00-0000-fe8f-5f110a0e0000 pid=3594 execve guuid=dd7878e6-1c00-0000-fe8f-5f110d0e0000 pid=3597 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=dd7878e6-1c00-0000-fe8f-5f110d0e0000 pid=3597 clone guuid=59f900e7-1c00-0000-fe8f-5f11100e0000 pid=3600 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=59f900e7-1c00-0000-fe8f-5f11100e0000 pid=3600 execve guuid=ec2566e7-1c00-0000-fe8f-5f11120e0000 pid=3602 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=ec2566e7-1c00-0000-fe8f-5f11120e0000 pid=3602 execve guuid=2ee1cbe7-1c00-0000-fe8f-5f11140e0000 pid=3604 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=2ee1cbe7-1c00-0000-fe8f-5f11140e0000 pid=3604 execve guuid=29ef5903-1d00-0000-fe8f-5f11510e0000 pid=3665 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=29ef5903-1d00-0000-fe8f-5f11510e0000 pid=3665 execve guuid=b3fb1c25-1d00-0000-fe8f-5f118e0e0000 pid=3726 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=b3fb1c25-1d00-0000-fe8f-5f118e0e0000 pid=3726 execve guuid=823dc725-1d00-0000-fe8f-5f118f0e0000 pid=3727 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=823dc725-1d00-0000-fe8f-5f118f0e0000 pid=3727 clone guuid=94f87626-1d00-0000-fe8f-5f11910e0000 pid=3729 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=94f87626-1d00-0000-fe8f-5f11910e0000 pid=3729 execve guuid=780e0d27-1d00-0000-fe8f-5f11920e0000 pid=3730 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=780e0d27-1d00-0000-fe8f-5f11920e0000 pid=3730 execve guuid=cae89327-1d00-0000-fe8f-5f11930e0000 pid=3731 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=cae89327-1d00-0000-fe8f-5f11930e0000 pid=3731 execve guuid=f31e9d44-1d00-0000-fe8f-5f11ec0e0000 pid=3820 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=f31e9d44-1d00-0000-fe8f-5f11ec0e0000 pid=3820 execve guuid=f647ed62-1d00-0000-fe8f-5f11480f0000 pid=3912 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=f647ed62-1d00-0000-fe8f-5f11480f0000 pid=3912 execve guuid=67973f63-1d00-0000-fe8f-5f114b0f0000 pid=3915 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=67973f63-1d00-0000-fe8f-5f114b0f0000 pid=3915 clone guuid=078f8863-1d00-0000-fe8f-5f114e0f0000 pid=3918 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=078f8863-1d00-0000-fe8f-5f114e0f0000 pid=3918 execve guuid=327fdd63-1d00-0000-fe8f-5f114f0f0000 pid=3919 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=327fdd63-1d00-0000-fe8f-5f114f0f0000 pid=3919 execve guuid=8bed4964-1d00-0000-fe8f-5f11520f0000 pid=3922 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=8bed4964-1d00-0000-fe8f-5f11520f0000 pid=3922 execve guuid=a20ee37f-1d00-0000-fe8f-5f11a00f0000 pid=4000 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=a20ee37f-1d00-0000-fe8f-5f11a00f0000 pid=4000 execve guuid=74d1e79f-1d00-0000-fe8f-5f11f50f0000 pid=4085 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=74d1e79f-1d00-0000-fe8f-5f11f50f0000 pid=4085 execve guuid=143c2fa0-1d00-0000-fe8f-5f11f60f0000 pid=4086 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=143c2fa0-1d00-0000-fe8f-5f11f60f0000 pid=4086 clone guuid=383c66a0-1d00-0000-fe8f-5f11fb0f0000 pid=4091 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=383c66a0-1d00-0000-fe8f-5f11fb0f0000 pid=4091 execve guuid=30d6c8a0-1d00-0000-fe8f-5f11fc0f0000 pid=4092 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=30d6c8a0-1d00-0000-fe8f-5f11fc0f0000 pid=4092 execve guuid=fb4344a1-1d00-0000-fe8f-5f1100100000 pid=4096 /usr/bin/wget net send-data guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=fb4344a1-1d00-0000-fe8f-5f1100100000 pid=4096 execve guuid=b35917be-1d00-0000-fe8f-5f1153100000 pid=4179 /usr/bin/curl net send-data write-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=b35917be-1d00-0000-fe8f-5f1153100000 pid=4179 execve guuid=e5c34edb-1d00-0000-fe8f-5f11a3100000 pid=4259 /usr/bin/chmod guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=e5c34edb-1d00-0000-fe8f-5f11a3100000 pid=4259 execve guuid=ecc0b0db-1d00-0000-fe8f-5f11a5100000 pid=4261 /usr/bin/bash guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=ecc0b0db-1d00-0000-fe8f-5f11a5100000 pid=4261 clone guuid=6823fedb-1d00-0000-fe8f-5f11a8100000 pid=4264 /usr/bin/rm delete-file guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=6823fedb-1d00-0000-fe8f-5f11a8100000 pid=4264 execve guuid=e33965dc-1d00-0000-fe8f-5f11aa100000 pid=4266 /usr/bin/rm guuid=6e49cbfd-1a00-0000-fe8f-5f11a00a0000 pid=2720->guuid=e33965dc-1d00-0000-fe8f-5f11aa100000 pid=4266 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=190086fe-1a00-0000-fe8f-5f11a40a0000 pid=2724->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=7ab9d31b-1b00-0000-fe8f-5f11d30a0000 pid=2771->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=8a08983e-1b00-0000-fe8f-5f11090b0000 pid=2825 /usr/bin/bash guuid=cd937d3e-1b00-0000-fe8f-5f11080b0000 pid=2824->guuid=8a08983e-1b00-0000-fe8f-5f11090b0000 pid=2825 clone guuid=23976d3f-1b00-0000-fe8f-5f110e0b0000 pid=2830->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=39a1ea5a-1b00-0000-fe8f-5f114a0b0000 pid=2890->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3955b97b-1b00-0000-fe8f-5f11850b0000 pid=2949 /usr/bin/bash guuid=24b8a07b-1b00-0000-fe8f-5f11830b0000 pid=2947->guuid=3955b97b-1b00-0000-fe8f-5f11850b0000 pid=2949 clone guuid=98d4ef7c-1b00-0000-fe8f-5f11880b0000 pid=2952->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=2beee798-1b00-0000-fe8f-5f11bd0b0000 pid=3005->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=48176eb8-1b00-0000-fe8f-5f11fc0b0000 pid=3068 /usr/bin/bash guuid=206c2bb8-1b00-0000-fe8f-5f11fb0b0000 pid=3067->guuid=48176eb8-1b00-0000-fe8f-5f11fc0b0000 pid=3068 clone guuid=af68a7b9-1b00-0000-fe8f-5f11010c0000 pid=3073->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4eee32d6-1b00-0000-fe8f-5f11390c0000 pid=3129->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=c3105ef5-1b00-0000-fe8f-5f117b0c0000 pid=3195 /usr/bin/bash guuid=362d45f5-1b00-0000-fe8f-5f117a0c0000 pid=3194->guuid=c3105ef5-1b00-0000-fe8f-5f117b0c0000 pid=3195 clone guuid=e7264bf6-1b00-0000-fe8f-5f11810c0000 pid=3201->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=57f05f12-1c00-0000-fe8f-5f11a60c0000 pid=3238->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=8b428030-1c00-0000-fe8f-5f11c70c0000 pid=3271 /usr/bin/bash guuid=04da5330-1c00-0000-fe8f-5f11c50c0000 pid=3269->guuid=8b428030-1c00-0000-fe8f-5f11c70c0000 pid=3271 clone guuid=5bd6ba31-1c00-0000-fe8f-5f11cc0c0000 pid=3276->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=56db134f-1c00-0000-fe8f-5f11f80c0000 pid=3320->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4d07d06e-1c00-0000-fe8f-5f11210d0000 pid=3361 /usr/bin/bash guuid=2488926e-1c00-0000-fe8f-5f11200d0000 pid=3360->guuid=4d07d06e-1c00-0000-fe8f-5f11210d0000 pid=3361 clone guuid=058f2c70-1c00-0000-fe8f-5f11240d0000 pid=3364->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=27a4e08b-1c00-0000-fe8f-5f114f0d0000 pid=3407->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=c79164ab-1c00-0000-fe8f-5f119c0d0000 pid=3484 /usr/bin/bash guuid=191942ab-1c00-0000-fe8f-5f119b0d0000 pid=3483->guuid=c79164ab-1c00-0000-fe8f-5f119c0d0000 pid=3484 clone guuid=c0ab4eac-1c00-0000-fe8f-5f11a20d0000 pid=3490->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=310172c8-1c00-0000-fe8f-5f11dc0d0000 pid=3548->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=97bba8e6-1c00-0000-fe8f-5f110e0e0000 pid=3598 /usr/bin/bash guuid=dd7878e6-1c00-0000-fe8f-5f110d0e0000 pid=3597->guuid=97bba8e6-1c00-0000-fe8f-5f110e0e0000 pid=3598 clone guuid=2ee1cbe7-1c00-0000-fe8f-5f11140e0000 pid=3604->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=29ef5903-1d00-0000-fe8f-5f11510e0000 pid=3665->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3d8d1326-1d00-0000-fe8f-5f11900e0000 pid=3728 /usr/bin/bash guuid=823dc725-1d00-0000-fe8f-5f118f0e0000 pid=3727->guuid=3d8d1326-1d00-0000-fe8f-5f11900e0000 pid=3728 clone guuid=cae89327-1d00-0000-fe8f-5f11930e0000 pid=3731->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f31e9d44-1d00-0000-fe8f-5f11ec0e0000 pid=3820->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=f09a5c63-1d00-0000-fe8f-5f114d0f0000 pid=3917 /usr/bin/bash guuid=67973f63-1d00-0000-fe8f-5f114b0f0000 pid=3915->guuid=f09a5c63-1d00-0000-fe8f-5f114d0f0000 pid=3917 clone guuid=8bed4964-1d00-0000-fe8f-5f11520f0000 pid=3922->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a20ee37f-1d00-0000-fe8f-5f11a00f0000 pid=4000->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=252e45a0-1d00-0000-fe8f-5f11fa0f0000 pid=4090 /usr/bin/bash guuid=143c2fa0-1d00-0000-fe8f-5f11f60f0000 pid=4086->guuid=252e45a0-1d00-0000-fe8f-5f11fa0f0000 pid=4090 clone guuid=fb4344a1-1d00-0000-fe8f-5f1100100000 pid=4096->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b35917be-1d00-0000-fe8f-5f1153100000 pid=4179->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=9d48d3db-1d00-0000-fe8f-5f11a7100000 pid=4263 /usr/bin/bash guuid=ecc0b0db-1d00-0000-fe8f-5f11a5100000 pid=4261->guuid=9d48d3db-1d00-0000-fe8f-5f11a7100000 pid=4263 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-08 13:55:42 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh abb381c26520d856f9d7f8ea742675c12c49fb95fbbd325007783153fcc2a617

(this sample)

  
Delivery method
Distributed via web download

Comments