MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf36a10bfb04d1d11c6d95a47f9d75aba0bee3a5fb208732a4c402a4494a2a8d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: bf36a10bfb04d1d11c6d95a47f9d75aba0bee3a5fb208732a4c402a4494a2a8d
SHA3-384 hash: 21d06cfecef10e58a48a040fca028f02c2896070f8683d0dfe68a219b70f02be61440919b8b6d51120f2a58a0a112178
SHA1 hash: 00ff68e4e238e5faca2d8505b98f8c5707aa0811
MD5 hash: a74584266b6eb534f431934048d40711
humanhash: tennis-london-early-illinois
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-23 06:53:32 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:53D9DSl5BZeF9eFD5FpFFlQ/QcVya4UL0:5zh457eneXXFHgJyaZL0
TLSH T1EC318AEE58105B3C1A13EA8E36A33548B00CE1FB6C5BC7A4DD491EE983986DC7162BC5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/3b48c1n/an/aelf ua-wget
http://5.182.210.61/95c879n/an/aelf ua-wget
http://5.182.210.61/50b182n/an/aelf ua-wget
http://5.182.210.61/082fe9n/an/aelf ua-wget
http://5.182.210.61/2e28fbn/an/aelf ua-wget
http://5.182.210.61/52d828n/an/aelf ua-wget
http://5.182.210.61/3a410bn/an/aelf ua-wget
http://5.182.210.61/e1e6c9n/an/aelf ua-wget
http://5.182.210.61/bb7e19n/an/aelf ua-wget
http://5.182.210.61/213b67n/an/aelf ua-wget
http://5.182.210.61/a09a82n/an/aelf ua-wget
http://5.182.210.61/85b314n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=da317c58-1900-0000-5c87-23de2e140000 pid=5166 /usr/bin/sudo guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167 /tmp/sample.bin guuid=da317c58-1900-0000-5c87-23de2e140000 pid=5166->guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167 execve guuid=12bb145c-1900-0000-5c87-23de30140000 pid=5168 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=12bb145c-1900-0000-5c87-23de30140000 pid=5168 execve guuid=3e1af860-1900-0000-5c87-23de31140000 pid=5169 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=3e1af860-1900-0000-5c87-23de31140000 pid=5169 execve guuid=ef87616a-1900-0000-5c87-23de32140000 pid=5170 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=ef87616a-1900-0000-5c87-23de32140000 pid=5170 execve guuid=750cc46a-1900-0000-5c87-23de33140000 pid=5171 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=750cc46a-1900-0000-5c87-23de33140000 pid=5171 clone guuid=b36e096b-1900-0000-5c87-23de35140000 pid=5173 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=b36e096b-1900-0000-5c87-23de35140000 pid=5173 execve guuid=5cf06a6b-1900-0000-5c87-23de36140000 pid=5174 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=5cf06a6b-1900-0000-5c87-23de36140000 pid=5174 execve guuid=53c7c96b-1900-0000-5c87-23de37140000 pid=5175 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=53c7c96b-1900-0000-5c87-23de37140000 pid=5175 execve guuid=03f5786e-1900-0000-5c87-23de38140000 pid=5176 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=03f5786e-1900-0000-5c87-23de38140000 pid=5176 execve guuid=7a261772-1900-0000-5c87-23de39140000 pid=5177 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=7a261772-1900-0000-5c87-23de39140000 pid=5177 execve guuid=ccc26972-1900-0000-5c87-23de3a140000 pid=5178 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=ccc26972-1900-0000-5c87-23de3a140000 pid=5178 clone guuid=8300b572-1900-0000-5c87-23de3c140000 pid=5180 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=8300b572-1900-0000-5c87-23de3c140000 pid=5180 execve guuid=5d971473-1900-0000-5c87-23de3d140000 pid=5181 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=5d971473-1900-0000-5c87-23de3d140000 pid=5181 execve guuid=1c767573-1900-0000-5c87-23de3e140000 pid=5182 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=1c767573-1900-0000-5c87-23de3e140000 pid=5182 execve guuid=94624e76-1900-0000-5c87-23de3f140000 pid=5183 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=94624e76-1900-0000-5c87-23de3f140000 pid=5183 execve guuid=94eb8c7a-1900-0000-5c87-23de43140000 pid=5187 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=94eb8c7a-1900-0000-5c87-23de43140000 pid=5187 execve guuid=4ad2447b-1900-0000-5c87-23de44140000 pid=5188 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=4ad2447b-1900-0000-5c87-23de44140000 pid=5188 clone guuid=b5c4ca7b-1900-0000-5c87-23de46140000 pid=5190 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=b5c4ca7b-1900-0000-5c87-23de46140000 pid=5190 execve guuid=fd13367c-1900-0000-5c87-23de47140000 pid=5191 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=fd13367c-1900-0000-5c87-23de47140000 pid=5191 execve guuid=a695a37c-1900-0000-5c87-23de48140000 pid=5192 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=a695a37c-1900-0000-5c87-23de48140000 pid=5192 execve guuid=541ac67f-1900-0000-5c87-23de4d140000 pid=5197 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=541ac67f-1900-0000-5c87-23de4d140000 pid=5197 execve guuid=47108484-1900-0000-5c87-23de4e140000 pid=5198 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=47108484-1900-0000-5c87-23de4e140000 pid=5198 execve guuid=d578e684-1900-0000-5c87-23de4f140000 pid=5199 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=d578e684-1900-0000-5c87-23de4f140000 pid=5199 clone guuid=cd35af85-1900-0000-5c87-23de51140000 pid=5201 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=cd35af85-1900-0000-5c87-23de51140000 pid=5201 execve guuid=41c23886-1900-0000-5c87-23de52140000 pid=5202 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=41c23886-1900-0000-5c87-23de52140000 pid=5202 execve guuid=ad468b86-1900-0000-5c87-23de53140000 pid=5203 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=ad468b86-1900-0000-5c87-23de53140000 pid=5203 execve guuid=6d35888a-1900-0000-5c87-23de54140000 pid=5204 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=6d35888a-1900-0000-5c87-23de54140000 pid=5204 execve guuid=438e3191-1900-0000-5c87-23de55140000 pid=5205 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=438e3191-1900-0000-5c87-23de55140000 pid=5205 execve guuid=b737aa91-1900-0000-5c87-23de56140000 pid=5206 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=b737aa91-1900-0000-5c87-23de56140000 pid=5206 clone guuid=07926a92-1900-0000-5c87-23de58140000 pid=5208 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=07926a92-1900-0000-5c87-23de58140000 pid=5208 execve guuid=563b5a93-1900-0000-5c87-23de59140000 pid=5209 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=563b5a93-1900-0000-5c87-23de59140000 pid=5209 execve guuid=4d3a0994-1900-0000-5c87-23de5a140000 pid=5210 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=4d3a0994-1900-0000-5c87-23de5a140000 pid=5210 execve guuid=3b2f899b-1900-0000-5c87-23de5b140000 pid=5211 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=3b2f899b-1900-0000-5c87-23de5b140000 pid=5211 execve guuid=316fa79f-1900-0000-5c87-23de5c140000 pid=5212 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=316fa79f-1900-0000-5c87-23de5c140000 pid=5212 execve guuid=21da21a0-1900-0000-5c87-23de5d140000 pid=5213 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=21da21a0-1900-0000-5c87-23de5d140000 pid=5213 clone guuid=a902afa0-1900-0000-5c87-23de5f140000 pid=5215 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=a902afa0-1900-0000-5c87-23de5f140000 pid=5215 execve guuid=f49435a1-1900-0000-5c87-23de60140000 pid=5216 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=f49435a1-1900-0000-5c87-23de60140000 pid=5216 execve guuid=b22f9ca1-1900-0000-5c87-23de61140000 pid=5217 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=b22f9ca1-1900-0000-5c87-23de61140000 pid=5217 execve guuid=2464f7a4-1900-0000-5c87-23de62140000 pid=5218 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=2464f7a4-1900-0000-5c87-23de62140000 pid=5218 execve guuid=f25d84a9-1900-0000-5c87-23de63140000 pid=5219 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=f25d84a9-1900-0000-5c87-23de63140000 pid=5219 execve guuid=52a0e9a9-1900-0000-5c87-23de64140000 pid=5220 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=52a0e9a9-1900-0000-5c87-23de64140000 pid=5220 clone guuid=186440aa-1900-0000-5c87-23de66140000 pid=5222 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=186440aa-1900-0000-5c87-23de66140000 pid=5222 execve guuid=3cf9cbaa-1900-0000-5c87-23de67140000 pid=5223 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=3cf9cbaa-1900-0000-5c87-23de67140000 pid=5223 execve guuid=c3af5dab-1900-0000-5c87-23de68140000 pid=5224 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=c3af5dab-1900-0000-5c87-23de68140000 pid=5224 execve guuid=58a63baf-1900-0000-5c87-23de69140000 pid=5225 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=58a63baf-1900-0000-5c87-23de69140000 pid=5225 execve guuid=737284b4-1900-0000-5c87-23de6a140000 pid=5226 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=737284b4-1900-0000-5c87-23de6a140000 pid=5226 execve guuid=579affb4-1900-0000-5c87-23de6b140000 pid=5227 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=579affb4-1900-0000-5c87-23de6b140000 pid=5227 clone guuid=b06467b5-1900-0000-5c87-23de6d140000 pid=5229 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=b06467b5-1900-0000-5c87-23de6d140000 pid=5229 execve guuid=a05dd0b5-1900-0000-5c87-23de6e140000 pid=5230 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=a05dd0b5-1900-0000-5c87-23de6e140000 pid=5230 execve guuid=0dac38b6-1900-0000-5c87-23de6f140000 pid=5231 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=0dac38b6-1900-0000-5c87-23de6f140000 pid=5231 execve guuid=44f4c9b9-1900-0000-5c87-23de70140000 pid=5232 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=44f4c9b9-1900-0000-5c87-23de70140000 pid=5232 execve guuid=164756bf-1900-0000-5c87-23de71140000 pid=5233 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=164756bf-1900-0000-5c87-23de71140000 pid=5233 execve guuid=5a79c0bf-1900-0000-5c87-23de72140000 pid=5234 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=5a79c0bf-1900-0000-5c87-23de72140000 pid=5234 clone guuid=bba12fc0-1900-0000-5c87-23de74140000 pid=5236 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=bba12fc0-1900-0000-5c87-23de74140000 pid=5236 execve guuid=0cb991c0-1900-0000-5c87-23de75140000 pid=5237 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=0cb991c0-1900-0000-5c87-23de75140000 pid=5237 execve guuid=297cedc0-1900-0000-5c87-23de76140000 pid=5238 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=297cedc0-1900-0000-5c87-23de76140000 pid=5238 execve guuid=82f7fbc3-1900-0000-5c87-23de77140000 pid=5239 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=82f7fbc3-1900-0000-5c87-23de77140000 pid=5239 execve guuid=5af2d3c9-1900-0000-5c87-23de78140000 pid=5240 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=5af2d3c9-1900-0000-5c87-23de78140000 pid=5240 execve guuid=aa9b2fca-1900-0000-5c87-23de79140000 pid=5241 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=aa9b2fca-1900-0000-5c87-23de79140000 pid=5241 clone guuid=106b7dca-1900-0000-5c87-23de7b140000 pid=5243 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=106b7dca-1900-0000-5c87-23de7b140000 pid=5243 execve guuid=d94dd5ca-1900-0000-5c87-23de7c140000 pid=5244 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=d94dd5ca-1900-0000-5c87-23de7c140000 pid=5244 execve guuid=ef0d25cb-1900-0000-5c87-23de7d140000 pid=5245 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=ef0d25cb-1900-0000-5c87-23de7d140000 pid=5245 execve guuid=f96440ce-1900-0000-5c87-23de7e140000 pid=5246 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=f96440ce-1900-0000-5c87-23de7e140000 pid=5246 execve guuid=7b0021d3-1900-0000-5c87-23de7f140000 pid=5247 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=7b0021d3-1900-0000-5c87-23de7f140000 pid=5247 execve guuid=a9ac8ed3-1900-0000-5c87-23de80140000 pid=5248 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=a9ac8ed3-1900-0000-5c87-23de80140000 pid=5248 clone guuid=f25af3d3-1900-0000-5c87-23de82140000 pid=5250 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=f25af3d3-1900-0000-5c87-23de82140000 pid=5250 execve guuid=a06a5bd4-1900-0000-5c87-23de83140000 pid=5251 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=a06a5bd4-1900-0000-5c87-23de83140000 pid=5251 execve guuid=1807bbd4-1900-0000-5c87-23de84140000 pid=5252 /usr/bin/wget net send-data guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=1807bbd4-1900-0000-5c87-23de84140000 pid=5252 execve guuid=afa47dd8-1900-0000-5c87-23de85140000 pid=5253 /usr/bin/curl net send-data write-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=afa47dd8-1900-0000-5c87-23de85140000 pid=5253 execve guuid=497701e2-1900-0000-5c87-23de86140000 pid=5254 /usr/bin/chmod guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=497701e2-1900-0000-5c87-23de86140000 pid=5254 execve guuid=4fcb70e2-1900-0000-5c87-23de87140000 pid=5255 /usr/bin/bash guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=4fcb70e2-1900-0000-5c87-23de87140000 pid=5255 clone guuid=1d9acae2-1900-0000-5c87-23de89140000 pid=5257 /usr/bin/rm delete-file guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=1d9acae2-1900-0000-5c87-23de89140000 pid=5257 execve guuid=9e4b48e3-1900-0000-5c87-23de8a140000 pid=5258 /usr/bin/rm guuid=c5ae9d5b-1900-0000-5c87-23de2f140000 pid=5167->guuid=9e4b48e3-1900-0000-5c87-23de8a140000 pid=5258 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=12bb145c-1900-0000-5c87-23de30140000 pid=5168->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=3e1af860-1900-0000-5c87-23de31140000 pid=5169->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=98c6e06a-1900-0000-5c87-23de34140000 pid=5172 /usr/bin/bash guuid=750cc46a-1900-0000-5c87-23de33140000 pid=5171->guuid=98c6e06a-1900-0000-5c87-23de34140000 pid=5172 clone guuid=53c7c96b-1900-0000-5c87-23de37140000 pid=5175->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=03f5786e-1900-0000-5c87-23de38140000 pid=5176->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=fada8672-1900-0000-5c87-23de3b140000 pid=5179 /usr/bin/bash guuid=ccc26972-1900-0000-5c87-23de3a140000 pid=5178->guuid=fada8672-1900-0000-5c87-23de3b140000 pid=5179 clone guuid=1c767573-1900-0000-5c87-23de3e140000 pid=5182->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=94624e76-1900-0000-5c87-23de3f140000 pid=5183->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=1616807b-1900-0000-5c87-23de45140000 pid=5189 /usr/bin/bash guuid=4ad2447b-1900-0000-5c87-23de44140000 pid=5188->guuid=1616807b-1900-0000-5c87-23de45140000 pid=5189 clone guuid=a695a37c-1900-0000-5c87-23de48140000 pid=5192->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=541ac67f-1900-0000-5c87-23de4d140000 pid=5197->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=1b1e7885-1900-0000-5c87-23de50140000 pid=5200 /usr/bin/bash guuid=d578e684-1900-0000-5c87-23de4f140000 pid=5199->guuid=1b1e7885-1900-0000-5c87-23de50140000 pid=5200 clone guuid=ad468b86-1900-0000-5c87-23de53140000 pid=5203->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=6d35888a-1900-0000-5c87-23de54140000 pid=5204->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=6013d691-1900-0000-5c87-23de57140000 pid=5207 /usr/bin/bash guuid=b737aa91-1900-0000-5c87-23de56140000 pid=5206->guuid=6013d691-1900-0000-5c87-23de57140000 pid=5207 clone guuid=4d3a0994-1900-0000-5c87-23de5a140000 pid=5210->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=3b2f899b-1900-0000-5c87-23de5b140000 pid=5211->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=6fa843a0-1900-0000-5c87-23de5e140000 pid=5214 /usr/bin/bash guuid=21da21a0-1900-0000-5c87-23de5d140000 pid=5213->guuid=6fa843a0-1900-0000-5c87-23de5e140000 pid=5214 clone guuid=b22f9ca1-1900-0000-5c87-23de61140000 pid=5217->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=2464f7a4-1900-0000-5c87-23de62140000 pid=5218->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=89d210aa-1900-0000-5c87-23de65140000 pid=5221 /usr/bin/bash guuid=52a0e9a9-1900-0000-5c87-23de64140000 pid=5220->guuid=89d210aa-1900-0000-5c87-23de65140000 pid=5221 clone guuid=c3af5dab-1900-0000-5c87-23de68140000 pid=5224->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=58a63baf-1900-0000-5c87-23de69140000 pid=5225->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=8a5329b5-1900-0000-5c87-23de6c140000 pid=5228 /usr/bin/bash guuid=579affb4-1900-0000-5c87-23de6b140000 pid=5227->guuid=8a5329b5-1900-0000-5c87-23de6c140000 pid=5228 clone guuid=0dac38b6-1900-0000-5c87-23de6f140000 pid=5231->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=44f4c9b9-1900-0000-5c87-23de70140000 pid=5232->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c447eabf-1900-0000-5c87-23de73140000 pid=5235 /usr/bin/bash guuid=5a79c0bf-1900-0000-5c87-23de72140000 pid=5234->guuid=c447eabf-1900-0000-5c87-23de73140000 pid=5235 clone guuid=297cedc0-1900-0000-5c87-23de76140000 pid=5238->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=82f7fbc3-1900-0000-5c87-23de77140000 pid=5239->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=6ef253ca-1900-0000-5c87-23de7a140000 pid=5242 /usr/bin/bash guuid=aa9b2fca-1900-0000-5c87-23de79140000 pid=5241->guuid=6ef253ca-1900-0000-5c87-23de7a140000 pid=5242 clone guuid=ef0d25cb-1900-0000-5c87-23de7d140000 pid=5245->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=f96440ce-1900-0000-5c87-23de7e140000 pid=5246->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=4ec9b6d3-1900-0000-5c87-23de81140000 pid=5249 /usr/bin/bash guuid=a9ac8ed3-1900-0000-5c87-23de80140000 pid=5248->guuid=4ec9b6d3-1900-0000-5c87-23de81140000 pid=5249 clone guuid=1807bbd4-1900-0000-5c87-23de84140000 pid=5252->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=afa47dd8-1900-0000-5c87-23de85140000 pid=5253->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=cff395e2-1900-0000-5c87-23de88140000 pid=5256 /usr/bin/bash guuid=4fcb70e2-1900-0000-5c87-23de87140000 pid=5255->guuid=cff395e2-1900-0000-5c87-23de88140000 pid=5256 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bf36a10bfb04d1d11c6d95a47f9d75aba0bee3a5fb208732a4c402a4494a2a8d

(this sample)

  
Delivery method
Distributed via web download

Comments