MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc786c43d85ae98751e34a655df52d53e0819b7add763b8ab348037aec89e47c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: bc786c43d85ae98751e34a655df52d53e0819b7add763b8ab348037aec89e47c
SHA3-384 hash: 2417371a717352a56c1ca54d2731555a92e4656565c7e3474226670e6af8a11c7566e41258884743e55fb2c00025b91a
SHA1 hash: 264ce6142dcac9b53f18be8c4ddfde50c1834860
MD5 hash: f125f59a8cc9305bdbdf13190e23c9d5
humanhash: april-football-nevada-magazine
File name:p
Download: download sample
File size:835 bytes
First seen:2026-06-19 07:11:51 UTC
Last seen:2026-06-20 03:19:29 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZoha5kSeeL8n6mSUu7:e9Qp+Ms5kSBYn65h7
TLSH T1A6016BDA4650A9004039DA9E76D751D0B521C3CE468F0BB87FDCAD3EFB88D04B066F98
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/E8On/an/aelf ua-wget
http://129.121.114.124/Un7Un/an/aelf ua-wget
http://129.121.114.124/OFtn/an/aelf ua-wget
http://129.121.114.124/ZLGLn/an/aelf ua-wget
http://129.121.114.124/b2Jn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-19T04:17:00Z UTC
Last seen:
2026-06-19T04:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=d41a7952-1900-0000-c512-f3c62e140000 pid=5166 /usr/bin/sudo guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167 /tmp/sample.bin write-file guuid=d41a7952-1900-0000-c512-f3c62e140000 pid=5166->guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167 execve guuid=9c016c55-1900-0000-c512-f3c630140000 pid=5168 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=9c016c55-1900-0000-c512-f3c630140000 pid=5168 execve guuid=dcb85c56-1900-0000-c512-f3c631140000 pid=5169 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=dcb85c56-1900-0000-c512-f3c631140000 pid=5169 execve guuid=9539da56-1900-0000-c512-f3c632140000 pid=5170 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=9539da56-1900-0000-c512-f3c632140000 pid=5170 execve guuid=bee75757-1900-0000-c512-f3c633140000 pid=5171 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=bee75757-1900-0000-c512-f3c633140000 pid=5171 execve guuid=eecfde57-1900-0000-c512-f3c634140000 pid=5172 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=eecfde57-1900-0000-c512-f3c634140000 pid=5172 execve guuid=5c4f5c58-1900-0000-c512-f3c635140000 pid=5173 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5c4f5c58-1900-0000-c512-f3c635140000 pid=5173 execve guuid=34cddb58-1900-0000-c512-f3c636140000 pid=5174 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=34cddb58-1900-0000-c512-f3c636140000 pid=5174 execve guuid=34515e59-1900-0000-c512-f3c637140000 pid=5175 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=34515e59-1900-0000-c512-f3c637140000 pid=5175 execve guuid=c7aad159-1900-0000-c512-f3c638140000 pid=5176 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=c7aad159-1900-0000-c512-f3c638140000 pid=5176 execve guuid=5e2c455a-1900-0000-c512-f3c639140000 pid=5177 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5e2c455a-1900-0000-c512-f3c639140000 pid=5177 execve guuid=c59db55a-1900-0000-c512-f3c63a140000 pid=5178 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=c59db55a-1900-0000-c512-f3c63a140000 pid=5178 execve guuid=0d8aa85b-1900-0000-c512-f3c63b140000 pid=5179 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0d8aa85b-1900-0000-c512-f3c63b140000 pid=5179 execve guuid=b57b215c-1900-0000-c512-f3c63c140000 pid=5180 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b57b215c-1900-0000-c512-f3c63c140000 pid=5180 execve guuid=9402955c-1900-0000-c512-f3c63d140000 pid=5181 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=9402955c-1900-0000-c512-f3c63d140000 pid=5181 execve guuid=b3cc135d-1900-0000-c512-f3c63e140000 pid=5182 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b3cc135d-1900-0000-c512-f3c63e140000 pid=5182 execve guuid=a5188c5d-1900-0000-c512-f3c63f140000 pid=5183 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=a5188c5d-1900-0000-c512-f3c63f140000 pid=5183 execve guuid=4f9c295e-1900-0000-c512-f3c640140000 pid=5184 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4f9c295e-1900-0000-c512-f3c640140000 pid=5184 execve guuid=0651eb5e-1900-0000-c512-f3c641140000 pid=5185 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0651eb5e-1900-0000-c512-f3c641140000 pid=5185 execve guuid=0a22825f-1900-0000-c512-f3c642140000 pid=5186 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0a22825f-1900-0000-c512-f3c642140000 pid=5186 execve guuid=0562f65f-1900-0000-c512-f3c643140000 pid=5187 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0562f65f-1900-0000-c512-f3c643140000 pid=5187 execve guuid=88e79b60-1900-0000-c512-f3c644140000 pid=5188 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=88e79b60-1900-0000-c512-f3c644140000 pid=5188 execve guuid=b9ec5161-1900-0000-c512-f3c645140000 pid=5189 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b9ec5161-1900-0000-c512-f3c645140000 pid=5189 execve guuid=c3e22b62-1900-0000-c512-f3c646140000 pid=5190 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=c3e22b62-1900-0000-c512-f3c646140000 pid=5190 execve guuid=a97afb62-1900-0000-c512-f3c647140000 pid=5191 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=a97afb62-1900-0000-c512-f3c647140000 pid=5191 execve guuid=b240cc63-1900-0000-c512-f3c648140000 pid=5192 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b240cc63-1900-0000-c512-f3c648140000 pid=5192 execve guuid=f4138f64-1900-0000-c512-f3c649140000 pid=5193 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f4138f64-1900-0000-c512-f3c649140000 pid=5193 execve guuid=4f271b65-1900-0000-c512-f3c64a140000 pid=5194 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4f271b65-1900-0000-c512-f3c64a140000 pid=5194 execve guuid=13b8a265-1900-0000-c512-f3c64b140000 pid=5195 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=13b8a265-1900-0000-c512-f3c64b140000 pid=5195 execve guuid=ff793066-1900-0000-c512-f3c64c140000 pid=5196 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ff793066-1900-0000-c512-f3c64c140000 pid=5196 execve guuid=f930b166-1900-0000-c512-f3c64d140000 pid=5197 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f930b166-1900-0000-c512-f3c64d140000 pid=5197 execve guuid=fde42f67-1900-0000-c512-f3c64e140000 pid=5198 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=fde42f67-1900-0000-c512-f3c64e140000 pid=5198 execve guuid=eb45b968-1900-0000-c512-f3c64f140000 pid=5199 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=eb45b968-1900-0000-c512-f3c64f140000 pid=5199 execve guuid=2f5c2769-1900-0000-c512-f3c650140000 pid=5200 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2f5c2769-1900-0000-c512-f3c650140000 pid=5200 execve guuid=cfd69469-1900-0000-c512-f3c651140000 pid=5201 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=cfd69469-1900-0000-c512-f3c651140000 pid=5201 execve guuid=92171f6a-1900-0000-c512-f3c652140000 pid=5202 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=92171f6a-1900-0000-c512-f3c652140000 pid=5202 execve guuid=124d8a6a-1900-0000-c512-f3c653140000 pid=5203 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=124d8a6a-1900-0000-c512-f3c653140000 pid=5203 execve guuid=2f93f36a-1900-0000-c512-f3c654140000 pid=5204 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2f93f36a-1900-0000-c512-f3c654140000 pid=5204 execve guuid=1b1e7d6b-1900-0000-c512-f3c655140000 pid=5205 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=1b1e7d6b-1900-0000-c512-f3c655140000 pid=5205 execve guuid=fe80e76b-1900-0000-c512-f3c656140000 pid=5206 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=fe80e76b-1900-0000-c512-f3c656140000 pid=5206 execve guuid=8b34516c-1900-0000-c512-f3c657140000 pid=5207 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8b34516c-1900-0000-c512-f3c657140000 pid=5207 execve guuid=920ac46c-1900-0000-c512-f3c658140000 pid=5208 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=920ac46c-1900-0000-c512-f3c658140000 pid=5208 execve guuid=a9d7366d-1900-0000-c512-f3c659140000 pid=5209 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=a9d7366d-1900-0000-c512-f3c659140000 pid=5209 execve guuid=f545a06d-1900-0000-c512-f3c65a140000 pid=5210 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f545a06d-1900-0000-c512-f3c65a140000 pid=5210 execve guuid=22eb156e-1900-0000-c512-f3c65b140000 pid=5211 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=22eb156e-1900-0000-c512-f3c65b140000 pid=5211 execve guuid=2654826e-1900-0000-c512-f3c65c140000 pid=5212 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2654826e-1900-0000-c512-f3c65c140000 pid=5212 execve guuid=ce70fe6e-1900-0000-c512-f3c65d140000 pid=5213 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ce70fe6e-1900-0000-c512-f3c65d140000 pid=5213 execve guuid=a86ff46f-1900-0000-c512-f3c65e140000 pid=5214 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=a86ff46f-1900-0000-c512-f3c65e140000 pid=5214 execve guuid=0bb56670-1900-0000-c512-f3c65f140000 pid=5215 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0bb56670-1900-0000-c512-f3c65f140000 pid=5215 execve guuid=dc3adf70-1900-0000-c512-f3c660140000 pid=5216 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=dc3adf70-1900-0000-c512-f3c660140000 pid=5216 execve guuid=5f865071-1900-0000-c512-f3c661140000 pid=5217 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5f865071-1900-0000-c512-f3c661140000 pid=5217 execve guuid=fdf6c671-1900-0000-c512-f3c662140000 pid=5218 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=fdf6c671-1900-0000-c512-f3c662140000 pid=5218 execve guuid=bb124472-1900-0000-c512-f3c663140000 pid=5219 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=bb124472-1900-0000-c512-f3c663140000 pid=5219 execve guuid=f9acbf72-1900-0000-c512-f3c664140000 pid=5220 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f9acbf72-1900-0000-c512-f3c664140000 pid=5220 execve guuid=b31d5e73-1900-0000-c512-f3c665140000 pid=5221 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b31d5e73-1900-0000-c512-f3c665140000 pid=5221 execve guuid=f864d273-1900-0000-c512-f3c666140000 pid=5222 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f864d273-1900-0000-c512-f3c666140000 pid=5222 execve guuid=68883e74-1900-0000-c512-f3c667140000 pid=5223 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=68883e74-1900-0000-c512-f3c667140000 pid=5223 execve guuid=4b51a774-1900-0000-c512-f3c668140000 pid=5224 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4b51a774-1900-0000-c512-f3c668140000 pid=5224 execve guuid=f0ab1575-1900-0000-c512-f3c669140000 pid=5225 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f0ab1575-1900-0000-c512-f3c669140000 pid=5225 execve guuid=fec18575-1900-0000-c512-f3c66a140000 pid=5226 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=fec18575-1900-0000-c512-f3c66a140000 pid=5226 execve guuid=41baf975-1900-0000-c512-f3c66b140000 pid=5227 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=41baf975-1900-0000-c512-f3c66b140000 pid=5227 execve guuid=77fe7276-1900-0000-c512-f3c66c140000 pid=5228 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=77fe7276-1900-0000-c512-f3c66c140000 pid=5228 execve guuid=2efbe976-1900-0000-c512-f3c66d140000 pid=5229 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2efbe976-1900-0000-c512-f3c66d140000 pid=5229 execve guuid=9a715977-1900-0000-c512-f3c66e140000 pid=5230 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=9a715977-1900-0000-c512-f3c66e140000 pid=5230 execve guuid=bb8cc377-1900-0000-c512-f3c66f140000 pid=5231 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=bb8cc377-1900-0000-c512-f3c66f140000 pid=5231 execve guuid=2b143c78-1900-0000-c512-f3c670140000 pid=5232 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2b143c78-1900-0000-c512-f3c670140000 pid=5232 execve guuid=8f7fa978-1900-0000-c512-f3c671140000 pid=5233 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8f7fa978-1900-0000-c512-f3c671140000 pid=5233 execve guuid=8e9b1779-1900-0000-c512-f3c672140000 pid=5234 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8e9b1779-1900-0000-c512-f3c672140000 pid=5234 execve guuid=96248379-1900-0000-c512-f3c673140000 pid=5235 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=96248379-1900-0000-c512-f3c673140000 pid=5235 execve guuid=8766e779-1900-0000-c512-f3c674140000 pid=5236 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8766e779-1900-0000-c512-f3c674140000 pid=5236 execve guuid=4a53597a-1900-0000-c512-f3c675140000 pid=5237 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4a53597a-1900-0000-c512-f3c675140000 pid=5237 execve guuid=5074c37a-1900-0000-c512-f3c676140000 pid=5238 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5074c37a-1900-0000-c512-f3c676140000 pid=5238 execve guuid=30a4317b-1900-0000-c512-f3c677140000 pid=5239 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=30a4317b-1900-0000-c512-f3c677140000 pid=5239 execve guuid=5d7ce47b-1900-0000-c512-f3c678140000 pid=5240 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5d7ce47b-1900-0000-c512-f3c678140000 pid=5240 execve guuid=631f527c-1900-0000-c512-f3c679140000 pid=5241 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=631f527c-1900-0000-c512-f3c679140000 pid=5241 execve guuid=612f1d7d-1900-0000-c512-f3c67a140000 pid=5242 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=612f1d7d-1900-0000-c512-f3c67a140000 pid=5242 execve guuid=2f3f957d-1900-0000-c512-f3c67b140000 pid=5243 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2f3f957d-1900-0000-c512-f3c67b140000 pid=5243 execve guuid=ae570a7e-1900-0000-c512-f3c67c140000 pid=5244 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ae570a7e-1900-0000-c512-f3c67c140000 pid=5244 execve guuid=ad86867e-1900-0000-c512-f3c67d140000 pid=5245 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ad86867e-1900-0000-c512-f3c67d140000 pid=5245 execve guuid=7090ff7e-1900-0000-c512-f3c67e140000 pid=5246 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=7090ff7e-1900-0000-c512-f3c67e140000 pid=5246 execve guuid=c1b5647f-1900-0000-c512-f3c67f140000 pid=5247 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=c1b5647f-1900-0000-c512-f3c67f140000 pid=5247 execve guuid=de49cf7f-1900-0000-c512-f3c680140000 pid=5248 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=de49cf7f-1900-0000-c512-f3c680140000 pid=5248 execve guuid=f7e73880-1900-0000-c512-f3c681140000 pid=5249 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f7e73880-1900-0000-c512-f3c681140000 pid=5249 execve guuid=0251a980-1900-0000-c512-f3c682140000 pid=5250 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0251a980-1900-0000-c512-f3c682140000 pid=5250 execve guuid=9dc61781-1900-0000-c512-f3c683140000 pid=5251 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=9dc61781-1900-0000-c512-f3c683140000 pid=5251 execve guuid=8a9e8c81-1900-0000-c512-f3c684140000 pid=5252 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8a9e8c81-1900-0000-c512-f3c684140000 pid=5252 execve guuid=0ada0282-1900-0000-c512-f3c685140000 pid=5253 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=0ada0282-1900-0000-c512-f3c685140000 pid=5253 execve guuid=7ab89782-1900-0000-c512-f3c686140000 pid=5254 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=7ab89782-1900-0000-c512-f3c686140000 pid=5254 execve guuid=7e6f3283-1900-0000-c512-f3c687140000 pid=5255 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=7e6f3283-1900-0000-c512-f3c687140000 pid=5255 execve guuid=6336b383-1900-0000-c512-f3c688140000 pid=5256 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=6336b383-1900-0000-c512-f3c688140000 pid=5256 execve guuid=d7b43584-1900-0000-c512-f3c689140000 pid=5257 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=d7b43584-1900-0000-c512-f3c689140000 pid=5257 execve guuid=8410b984-1900-0000-c512-f3c68a140000 pid=5258 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8410b984-1900-0000-c512-f3c68a140000 pid=5258 execve guuid=6bc03a85-1900-0000-c512-f3c68b140000 pid=5259 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=6bc03a85-1900-0000-c512-f3c68b140000 pid=5259 execve guuid=bf89bc85-1900-0000-c512-f3c68c140000 pid=5260 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=bf89bc85-1900-0000-c512-f3c68c140000 pid=5260 execve guuid=c9da4286-1900-0000-c512-f3c68d140000 pid=5261 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=c9da4286-1900-0000-c512-f3c68d140000 pid=5261 execve guuid=bf89b586-1900-0000-c512-f3c68e140000 pid=5262 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=bf89b586-1900-0000-c512-f3c68e140000 pid=5262 execve guuid=a7942d87-1900-0000-c512-f3c68f140000 pid=5263 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=a7942d87-1900-0000-c512-f3c68f140000 pid=5263 execve guuid=5a65f987-1900-0000-c512-f3c690140000 pid=5264 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5a65f987-1900-0000-c512-f3c690140000 pid=5264 execve guuid=3823c788-1900-0000-c512-f3c691140000 pid=5265 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=3823c788-1900-0000-c512-f3c691140000 pid=5265 execve guuid=1ad08a89-1900-0000-c512-f3c692140000 pid=5266 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=1ad08a89-1900-0000-c512-f3c692140000 pid=5266 execve guuid=da222f8a-1900-0000-c512-f3c693140000 pid=5267 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=da222f8a-1900-0000-c512-f3c693140000 pid=5267 execve guuid=2e13d28a-1900-0000-c512-f3c694140000 pid=5268 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2e13d28a-1900-0000-c512-f3c694140000 pid=5268 execve guuid=49a23b8b-1900-0000-c512-f3c695140000 pid=5269 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=49a23b8b-1900-0000-c512-f3c695140000 pid=5269 execve guuid=c2bca18b-1900-0000-c512-f3c696140000 pid=5270 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=c2bca18b-1900-0000-c512-f3c696140000 pid=5270 execve guuid=1fc0fe8b-1900-0000-c512-f3c697140000 pid=5271 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=1fc0fe8b-1900-0000-c512-f3c697140000 pid=5271 execve guuid=ddff688c-1900-0000-c512-f3c698140000 pid=5272 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ddff688c-1900-0000-c512-f3c698140000 pid=5272 execve guuid=4dcae28c-1900-0000-c512-f3c699140000 pid=5273 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4dcae28c-1900-0000-c512-f3c699140000 pid=5273 execve guuid=ebf4468d-1900-0000-c512-f3c69a140000 pid=5274 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ebf4468d-1900-0000-c512-f3c69a140000 pid=5274 execve guuid=8c4aa78d-1900-0000-c512-f3c69b140000 pid=5275 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8c4aa78d-1900-0000-c512-f3c69b140000 pid=5275 execve guuid=fa7c768e-1900-0000-c512-f3c69c140000 pid=5276 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=fa7c768e-1900-0000-c512-f3c69c140000 pid=5276 execve guuid=638fda8e-1900-0000-c512-f3c69d140000 pid=5277 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=638fda8e-1900-0000-c512-f3c69d140000 pid=5277 execve guuid=6d20458f-1900-0000-c512-f3c69e140000 pid=5278 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=6d20458f-1900-0000-c512-f3c69e140000 pid=5278 execve guuid=3121af8f-1900-0000-c512-f3c69f140000 pid=5279 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=3121af8f-1900-0000-c512-f3c69f140000 pid=5279 execve guuid=609f2f90-1900-0000-c512-f3c6a0140000 pid=5280 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=609f2f90-1900-0000-c512-f3c6a0140000 pid=5280 execve guuid=abe3c890-1900-0000-c512-f3c6a1140000 pid=5281 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=abe3c890-1900-0000-c512-f3c6a1140000 pid=5281 execve guuid=da266791-1900-0000-c512-f3c6a2140000 pid=5282 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=da266791-1900-0000-c512-f3c6a2140000 pid=5282 execve guuid=59050c92-1900-0000-c512-f3c6a3140000 pid=5283 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=59050c92-1900-0000-c512-f3c6a3140000 pid=5283 execve guuid=438fb592-1900-0000-c512-f3c6a4140000 pid=5284 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=438fb592-1900-0000-c512-f3c6a4140000 pid=5284 execve guuid=ea247893-1900-0000-c512-f3c6a5140000 pid=5285 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ea247893-1900-0000-c512-f3c6a5140000 pid=5285 execve guuid=78043494-1900-0000-c512-f3c6a6140000 pid=5286 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=78043494-1900-0000-c512-f3c6a6140000 pid=5286 execve guuid=5bd3f094-1900-0000-c512-f3c6a7140000 pid=5287 /usr/bin/ls guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=5bd3f094-1900-0000-c512-f3c6a7140000 pid=5287 execve guuid=dd589695-1900-0000-c512-f3c6a8140000 pid=5288 /usr/bin/rm guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=dd589695-1900-0000-c512-f3c6a8140000 pid=5288 execve guuid=87b40996-1900-0000-c512-f3c6a9140000 pid=5289 /usr/bin/wget net send-data write-file guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=87b40996-1900-0000-c512-f3c6a9140000 pid=5289 execve guuid=8b849ea5-1900-0000-c512-f3c6aa140000 pid=5290 /usr/bin/chmod guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8b849ea5-1900-0000-c512-f3c6aa140000 pid=5290 execve guuid=591813a6-1900-0000-c512-f3c6ab140000 pid=5291 /tmp/E8O guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=591813a6-1900-0000-c512-f3c6ab140000 pid=5291 execve guuid=2fb5eda6-1900-0000-c512-f3c6ad140000 pid=5293 /usr/bin/rm guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2fb5eda6-1900-0000-c512-f3c6ad140000 pid=5293 execve guuid=f83d52a7-1900-0000-c512-f3c6ae140000 pid=5294 /usr/bin/wget net send-data write-file guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=f83d52a7-1900-0000-c512-f3c6ae140000 pid=5294 execve guuid=e73da8b4-1900-0000-c512-f3c6af140000 pid=5295 /usr/bin/chmod guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=e73da8b4-1900-0000-c512-f3c6af140000 pid=5295 execve guuid=ee8c01b5-1900-0000-c512-f3c6b0140000 pid=5296 /tmp/Un7U guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=ee8c01b5-1900-0000-c512-f3c6b0140000 pid=5296 execve guuid=8a16f2b5-1900-0000-c512-f3c6b2140000 pid=5298 /usr/bin/rm guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=8a16f2b5-1900-0000-c512-f3c6b2140000 pid=5298 execve guuid=a8078bb6-1900-0000-c512-f3c6b3140000 pid=5299 /usr/bin/wget net send-data write-file guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=a8078bb6-1900-0000-c512-f3c6b3140000 pid=5299 execve guuid=4432c9c4-1900-0000-c512-f3c6b4140000 pid=5300 /usr/bin/chmod guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4432c9c4-1900-0000-c512-f3c6b4140000 pid=5300 execve guuid=65b21fc5-1900-0000-c512-f3c6b5140000 pid=5301 /tmp/OFt guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=65b21fc5-1900-0000-c512-f3c6b5140000 pid=5301 execve guuid=1718ebc5-1900-0000-c512-f3c6b7140000 pid=5303 /usr/bin/rm guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=1718ebc5-1900-0000-c512-f3c6b7140000 pid=5303 execve guuid=b4ca33c6-1900-0000-c512-f3c6b8140000 pid=5304 /usr/bin/wget net send-data write-file guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b4ca33c6-1900-0000-c512-f3c6b8140000 pid=5304 execve guuid=2fa6e3d2-1900-0000-c512-f3c6b9140000 pid=5305 /usr/bin/chmod guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=2fa6e3d2-1900-0000-c512-f3c6b9140000 pid=5305 execve guuid=9c922fd3-1900-0000-c512-f3c6ba140000 pid=5306 /tmp/ZLGL guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=9c922fd3-1900-0000-c512-f3c6ba140000 pid=5306 execve guuid=d17dfcd3-1900-0000-c512-f3c6bc140000 pid=5308 /usr/bin/rm guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=d17dfcd3-1900-0000-c512-f3c6bc140000 pid=5308 execve guuid=4c8942d4-1900-0000-c512-f3c6bd140000 pid=5309 /usr/bin/wget net send-data write-file guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=4c8942d4-1900-0000-c512-f3c6bd140000 pid=5309 execve guuid=718640e1-1900-0000-c512-f3c6c5140000 pid=5317 /usr/bin/chmod guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=718640e1-1900-0000-c512-f3c6c5140000 pid=5317 execve guuid=05adbee1-1900-0000-c512-f3c6c6140000 pid=5318 /tmp/b2J guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=05adbee1-1900-0000-c512-f3c6c6140000 pid=5318 execve guuid=b99d41e3-1900-0000-c512-f3c6c8140000 pid=5320 /usr/bin/rm delete-file guuid=7766dc54-1900-0000-c512-f3c62f140000 pid=5167->guuid=b99d41e3-1900-0000-c512-f3c6c8140000 pid=5320 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=87b40996-1900-0000-c512-f3c6a9140000 pid=5289->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=f83d52a7-1900-0000-c512-f3c6ae140000 pid=5294->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=a8078bb6-1900-0000-c512-f3c6b3140000 pid=5299->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=b4ca33c6-1900-0000-c512-f3c6b8140000 pid=5304->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=4c8942d4-1900-0000-c512-f3c6bd140000 pid=5309->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-19 07:12:56 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Enumerates running processes
Reads hardware information
Reads list of loaded kernel modules
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bc786c43d85ae98751e34a655df52d53e0819b7add763b8ab348037aec89e47c

(this sample)

  
Delivery method
Distributed via web download

Comments