MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c96ede852e613ff8a8d82fca5e0a9d65583effbb40e08cbcb5447141d33f7408. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: c96ede852e613ff8a8d82fca5e0a9d65583effbb40e08cbcb5447141d33f7408
SHA3-384 hash: 6ecad4f7ebddb3c70e2235e2c5d458c3c7910a6abfcd45818806b24355a4d5b2756a0d36815d87ffc19e7da6b02a2031
SHA1 hash: 8b052891f29e32706c37c5913d054d5afcb0c9d7
MD5 hash: 2927ccfb7187564241fe1adb1a691280
humanhash: lactose-echo-potato-fruit
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-18 15:36:45 UTC
Last seen:2026-06-19 10:03:26 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UE6zsfFxU6+G6JmNH6ltBxDNoB6NoPis+i6+Le9i62HAE36fzLX6Lg5OfWF6ML6O:83vxujKQepn5MWFNhOhXERXXI+V
TLSH T13531748B1014163A1202CEDDB3A77148750DC9EB2D9BC7A49C4D0FFA82882DDB221FD5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/8df859n/an/aua-wget
http://5.182.210.61/43304bn/an/aua-wget
http://5.182.210.61/1d1781n/an/aua-wget
http://5.182.210.61/310fe4n/an/aua-wget
http://5.182.210.61/d4eb8an/an/aua-wget
http://5.182.210.61/51d33en/an/aua-wget
http://5.182.210.61/990398n/an/aua-wget
http://5.182.210.61/7be221n/an/aua-wget
http://5.182.210.61/3eca8en/an/aua-wget
http://5.182.210.61/9f42d9n/an/aua-wget
http://5.182.210.61/83e595n/an/aua-wget
http://5.182.210.61/a098f9n/an/aua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-18T12:48:00Z UTC
Last seen:
2026-06-19T00:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f38583a2-1a00-0000-3da6-7b0ae20c0000 pid=3298 /usr/bin/sudo guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304 /tmp/sample.bin guuid=f38583a2-1a00-0000-3da6-7b0ae20c0000 pid=3298->guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304 execve guuid=b965bea4-1a00-0000-3da6-7b0ae90c0000 pid=3305 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=b965bea4-1a00-0000-3da6-7b0ae90c0000 pid=3305 execve guuid=e2503da8-1a00-0000-3da6-7b0af40c0000 pid=3316 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=e2503da8-1a00-0000-3da6-7b0af40c0000 pid=3316 execve guuid=84f36cb1-1a00-0000-3da6-7b0a010d0000 pid=3329 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=84f36cb1-1a00-0000-3da6-7b0a010d0000 pid=3329 execve guuid=28c2e5b1-1a00-0000-3da6-7b0a040d0000 pid=3332 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=28c2e5b1-1a00-0000-3da6-7b0a040d0000 pid=3332 clone guuid=6f8e24b2-1a00-0000-3da6-7b0a060d0000 pid=3334 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=6f8e24b2-1a00-0000-3da6-7b0a060d0000 pid=3334 execve guuid=53f06bb2-1a00-0000-3da6-7b0a080d0000 pid=3336 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=53f06bb2-1a00-0000-3da6-7b0a080d0000 pid=3336 execve guuid=d018adb2-1a00-0000-3da6-7b0a090d0000 pid=3337 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=d018adb2-1a00-0000-3da6-7b0a090d0000 pid=3337 execve guuid=327ac7c2-1a00-0000-3da6-7b0a380d0000 pid=3384 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=327ac7c2-1a00-0000-3da6-7b0a380d0000 pid=3384 execve guuid=e528eec7-1a00-0000-3da6-7b0a480d0000 pid=3400 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=e528eec7-1a00-0000-3da6-7b0a480d0000 pid=3400 execve guuid=479f3ac8-1a00-0000-3da6-7b0a490d0000 pid=3401 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=479f3ac8-1a00-0000-3da6-7b0a490d0000 pid=3401 clone guuid=a83571c8-1a00-0000-3da6-7b0a4c0d0000 pid=3404 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=a83571c8-1a00-0000-3da6-7b0a4c0d0000 pid=3404 execve guuid=9373bac8-1a00-0000-3da6-7b0a4e0d0000 pid=3406 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=9373bac8-1a00-0000-3da6-7b0a4e0d0000 pid=3406 execve guuid=1f6504c9-1a00-0000-3da6-7b0a500d0000 pid=3408 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=1f6504c9-1a00-0000-3da6-7b0a500d0000 pid=3408 execve guuid=6ac293cb-1a00-0000-3da6-7b0a590d0000 pid=3417 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=6ac293cb-1a00-0000-3da6-7b0a590d0000 pid=3417 execve guuid=0985a0cf-1a00-0000-3da6-7b0a670d0000 pid=3431 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=0985a0cf-1a00-0000-3da6-7b0a670d0000 pid=3431 execve guuid=5a94e5cf-1a00-0000-3da6-7b0a680d0000 pid=3432 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=5a94e5cf-1a00-0000-3da6-7b0a680d0000 pid=3432 clone guuid=352023d0-1a00-0000-3da6-7b0a6b0d0000 pid=3435 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=352023d0-1a00-0000-3da6-7b0a6b0d0000 pid=3435 execve guuid=ae0c7bd0-1a00-0000-3da6-7b0a6d0d0000 pid=3437 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=ae0c7bd0-1a00-0000-3da6-7b0a6d0d0000 pid=3437 execve guuid=5172e9d0-1a00-0000-3da6-7b0a6f0d0000 pid=3439 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=5172e9d0-1a00-0000-3da6-7b0a6f0d0000 pid=3439 execve guuid=522bded4-1a00-0000-3da6-7b0a7b0d0000 pid=3451 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=522bded4-1a00-0000-3da6-7b0a7b0d0000 pid=3451 execve guuid=38d70bda-1a00-0000-3da6-7b0a890d0000 pid=3465 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=38d70bda-1a00-0000-3da6-7b0a890d0000 pid=3465 execve guuid=69834fda-1a00-0000-3da6-7b0a8a0d0000 pid=3466 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=69834fda-1a00-0000-3da6-7b0a8a0d0000 pid=3466 clone guuid=300c89da-1a00-0000-3da6-7b0a8c0d0000 pid=3468 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=300c89da-1a00-0000-3da6-7b0a8c0d0000 pid=3468 execve guuid=e2a3d2da-1a00-0000-3da6-7b0a8d0d0000 pid=3469 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=e2a3d2da-1a00-0000-3da6-7b0a8d0d0000 pid=3469 execve guuid=757713db-1a00-0000-3da6-7b0a8e0d0000 pid=3470 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=757713db-1a00-0000-3da6-7b0a8e0d0000 pid=3470 execve guuid=983da5dd-1a00-0000-3da6-7b0a920d0000 pid=3474 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=983da5dd-1a00-0000-3da6-7b0a920d0000 pid=3474 execve guuid=acd77de1-1a00-0000-3da6-7b0a9d0d0000 pid=3485 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=acd77de1-1a00-0000-3da6-7b0a9d0d0000 pid=3485 execve guuid=8c85d0e1-1a00-0000-3da6-7b0a9e0d0000 pid=3486 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=8c85d0e1-1a00-0000-3da6-7b0a9e0d0000 pid=3486 clone guuid=ecaa0ce2-1a00-0000-3da6-7b0aa10d0000 pid=3489 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=ecaa0ce2-1a00-0000-3da6-7b0aa10d0000 pid=3489 execve guuid=596a4fe2-1a00-0000-3da6-7b0aa20d0000 pid=3490 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=596a4fe2-1a00-0000-3da6-7b0aa20d0000 pid=3490 execve guuid=9ed792e2-1a00-0000-3da6-7b0aa30d0000 pid=3491 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=9ed792e2-1a00-0000-3da6-7b0aa30d0000 pid=3491 execve guuid=df1d3ce5-1a00-0000-3da6-7b0aab0d0000 pid=3499 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=df1d3ce5-1a00-0000-3da6-7b0aab0d0000 pid=3499 execve guuid=f0a438ea-1a00-0000-3da6-7b0ab80d0000 pid=3512 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=f0a438ea-1a00-0000-3da6-7b0ab80d0000 pid=3512 execve guuid=5f40abea-1a00-0000-3da6-7b0aba0d0000 pid=3514 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=5f40abea-1a00-0000-3da6-7b0aba0d0000 pid=3514 clone guuid=c9ffe9ea-1a00-0000-3da6-7b0abd0d0000 pid=3517 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=c9ffe9ea-1a00-0000-3da6-7b0abd0d0000 pid=3517 execve guuid=4bb943eb-1a00-0000-3da6-7b0abf0d0000 pid=3519 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=4bb943eb-1a00-0000-3da6-7b0abf0d0000 pid=3519 execve guuid=900999eb-1a00-0000-3da6-7b0ac10d0000 pid=3521 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=900999eb-1a00-0000-3da6-7b0ac10d0000 pid=3521 execve guuid=768f85ee-1a00-0000-3da6-7b0ac60d0000 pid=3526 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=768f85ee-1a00-0000-3da6-7b0ac60d0000 pid=3526 execve guuid=464908f4-1a00-0000-3da6-7b0ad80d0000 pid=3544 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=464908f4-1a00-0000-3da6-7b0ad80d0000 pid=3544 execve guuid=938b46f4-1a00-0000-3da6-7b0ad90d0000 pid=3545 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=938b46f4-1a00-0000-3da6-7b0ad90d0000 pid=3545 clone guuid=cbce97f4-1a00-0000-3da6-7b0add0d0000 pid=3549 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=cbce97f4-1a00-0000-3da6-7b0add0d0000 pid=3549 execve guuid=e632d8f4-1a00-0000-3da6-7b0adf0d0000 pid=3551 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=e632d8f4-1a00-0000-3da6-7b0adf0d0000 pid=3551 execve guuid=409411f5-1a00-0000-3da6-7b0ae00d0000 pid=3552 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=409411f5-1a00-0000-3da6-7b0ae00d0000 pid=3552 execve guuid=2c1f84f7-1a00-0000-3da6-7b0aec0d0000 pid=3564 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=2c1f84f7-1a00-0000-3da6-7b0aec0d0000 pid=3564 execve guuid=12c99afd-1a00-0000-3da6-7b0af80d0000 pid=3576 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=12c99afd-1a00-0000-3da6-7b0af80d0000 pid=3576 execve guuid=a5d81efe-1a00-0000-3da6-7b0afb0d0000 pid=3579 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=a5d81efe-1a00-0000-3da6-7b0afb0d0000 pid=3579 clone guuid=c39b6efe-1a00-0000-3da6-7b0afe0d0000 pid=3582 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=c39b6efe-1a00-0000-3da6-7b0afe0d0000 pid=3582 execve guuid=53fbc2fe-1a00-0000-3da6-7b0a000e0000 pid=3584 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=53fbc2fe-1a00-0000-3da6-7b0a000e0000 pid=3584 execve guuid=1aa01fff-1a00-0000-3da6-7b0a020e0000 pid=3586 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=1aa01fff-1a00-0000-3da6-7b0a020e0000 pid=3586 execve guuid=70c00102-1b00-0000-3da6-7b0a0b0e0000 pid=3595 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=70c00102-1b00-0000-3da6-7b0a0b0e0000 pid=3595 execve guuid=07308206-1b00-0000-3da6-7b0a170e0000 pid=3607 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=07308206-1b00-0000-3da6-7b0a170e0000 pid=3607 execve guuid=dcbfdd06-1b00-0000-3da6-7b0a190e0000 pid=3609 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=dcbfdd06-1b00-0000-3da6-7b0a190e0000 pid=3609 clone guuid=5a7d3207-1b00-0000-3da6-7b0a1c0e0000 pid=3612 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=5a7d3207-1b00-0000-3da6-7b0a1c0e0000 pid=3612 execve guuid=1eb6ce07-1b00-0000-3da6-7b0a1e0e0000 pid=3614 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=1eb6ce07-1b00-0000-3da6-7b0a1e0e0000 pid=3614 execve guuid=f1643a08-1b00-0000-3da6-7b0a200e0000 pid=3616 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=f1643a08-1b00-0000-3da6-7b0a200e0000 pid=3616 execve guuid=51dc060b-1b00-0000-3da6-7b0a270e0000 pid=3623 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=51dc060b-1b00-0000-3da6-7b0a270e0000 pid=3623 execve guuid=f7bae40f-1b00-0000-3da6-7b0a390e0000 pid=3641 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=f7bae40f-1b00-0000-3da6-7b0a390e0000 pid=3641 execve guuid=35ef2d10-1b00-0000-3da6-7b0a3a0e0000 pid=3642 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=35ef2d10-1b00-0000-3da6-7b0a3a0e0000 pid=3642 clone guuid=7c275e10-1b00-0000-3da6-7b0a3f0e0000 pid=3647 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=7c275e10-1b00-0000-3da6-7b0a3f0e0000 pid=3647 execve guuid=04019f10-1b00-0000-3da6-7b0a400e0000 pid=3648 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=04019f10-1b00-0000-3da6-7b0a400e0000 pid=3648 execve guuid=d5f9e410-1b00-0000-3da6-7b0a420e0000 pid=3650 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=d5f9e410-1b00-0000-3da6-7b0a420e0000 pid=3650 execve guuid=20305b13-1b00-0000-3da6-7b0a4a0e0000 pid=3658 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=20305b13-1b00-0000-3da6-7b0a4a0e0000 pid=3658 execve guuid=bc740118-1b00-0000-3da6-7b0a520e0000 pid=3666 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=bc740118-1b00-0000-3da6-7b0a520e0000 pid=3666 execve guuid=91db7318-1b00-0000-3da6-7b0a540e0000 pid=3668 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=91db7318-1b00-0000-3da6-7b0a540e0000 pid=3668 clone guuid=e227b618-1b00-0000-3da6-7b0a560e0000 pid=3670 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=e227b618-1b00-0000-3da6-7b0a560e0000 pid=3670 execve guuid=34ff0019-1b00-0000-3da6-7b0a580e0000 pid=3672 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=34ff0019-1b00-0000-3da6-7b0a580e0000 pid=3672 execve guuid=8e7f7119-1b00-0000-3da6-7b0a5b0e0000 pid=3675 /usr/bin/wget net send-data guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=8e7f7119-1b00-0000-3da6-7b0a5b0e0000 pid=3675 execve guuid=21e53c1d-1b00-0000-3da6-7b0a650e0000 pid=3685 /usr/bin/curl net send-data write-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=21e53c1d-1b00-0000-3da6-7b0a650e0000 pid=3685 execve guuid=4625ef20-1b00-0000-3da6-7b0a6c0e0000 pid=3692 /usr/bin/chmod guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=4625ef20-1b00-0000-3da6-7b0a6c0e0000 pid=3692 execve guuid=1e4c5221-1b00-0000-3da6-7b0a6d0e0000 pid=3693 /usr/bin/bash guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=1e4c5221-1b00-0000-3da6-7b0a6d0e0000 pid=3693 clone guuid=a6eddd21-1b00-0000-3da6-7b0a6f0e0000 pid=3695 /usr/bin/rm delete-file guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=a6eddd21-1b00-0000-3da6-7b0a6f0e0000 pid=3695 execve guuid=a2524522-1b00-0000-3da6-7b0a700e0000 pid=3696 /usr/bin/rm guuid=1bd649a4-1a00-0000-3da6-7b0ae80c0000 pid=3304->guuid=a2524522-1b00-0000-3da6-7b0a700e0000 pid=3696 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=b965bea4-1a00-0000-3da6-7b0ae90c0000 pid=3305->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=e2503da8-1a00-0000-3da6-7b0af40c0000 pid=3316->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ce8dfbb1-1a00-0000-3da6-7b0a050d0000 pid=3333 /usr/bin/bash guuid=28c2e5b1-1a00-0000-3da6-7b0a040d0000 pid=3332->guuid=ce8dfbb1-1a00-0000-3da6-7b0a050d0000 pid=3333 clone guuid=d018adb2-1a00-0000-3da6-7b0a090d0000 pid=3337->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=327ac7c2-1a00-0000-3da6-7b0a380d0000 pid=3384->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=980b53c8-1a00-0000-3da6-7b0a4b0d0000 pid=3403 /usr/bin/bash guuid=479f3ac8-1a00-0000-3da6-7b0a490d0000 pid=3401->guuid=980b53c8-1a00-0000-3da6-7b0a4b0d0000 pid=3403 clone guuid=1f6504c9-1a00-0000-3da6-7b0a500d0000 pid=3408->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=6ac293cb-1a00-0000-3da6-7b0a590d0000 pid=3417->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=f252fdcf-1a00-0000-3da6-7b0a690d0000 pid=3433 /usr/bin/bash guuid=5a94e5cf-1a00-0000-3da6-7b0a680d0000 pid=3432->guuid=f252fdcf-1a00-0000-3da6-7b0a690d0000 pid=3433 clone guuid=5172e9d0-1a00-0000-3da6-7b0a6f0d0000 pid=3439->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=522bded4-1a00-0000-3da6-7b0a7b0d0000 pid=3451->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c7a166da-1a00-0000-3da6-7b0a8b0d0000 pid=3467 /usr/bin/bash guuid=69834fda-1a00-0000-3da6-7b0a8a0d0000 pid=3466->guuid=c7a166da-1a00-0000-3da6-7b0a8b0d0000 pid=3467 clone guuid=757713db-1a00-0000-3da6-7b0a8e0d0000 pid=3470->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=983da5dd-1a00-0000-3da6-7b0a920d0000 pid=3474->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=417ae8e1-1a00-0000-3da6-7b0a9f0d0000 pid=3487 /usr/bin/bash guuid=8c85d0e1-1a00-0000-3da6-7b0a9e0d0000 pid=3486->guuid=417ae8e1-1a00-0000-3da6-7b0a9f0d0000 pid=3487 clone guuid=9ed792e2-1a00-0000-3da6-7b0aa30d0000 pid=3491->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=df1d3ce5-1a00-0000-3da6-7b0aab0d0000 pid=3499->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0f4accea-1a00-0000-3da6-7b0abb0d0000 pid=3515 /usr/bin/bash guuid=5f40abea-1a00-0000-3da6-7b0aba0d0000 pid=3514->guuid=0f4accea-1a00-0000-3da6-7b0abb0d0000 pid=3515 clone guuid=900999eb-1a00-0000-3da6-7b0ac10d0000 pid=3521->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=768f85ee-1a00-0000-3da6-7b0ac60d0000 pid=3526->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=75ae61f4-1a00-0000-3da6-7b0adb0d0000 pid=3547 /usr/bin/bash guuid=938b46f4-1a00-0000-3da6-7b0ad90d0000 pid=3545->guuid=75ae61f4-1a00-0000-3da6-7b0adb0d0000 pid=3547 clone guuid=409411f5-1a00-0000-3da6-7b0ae00d0000 pid=3552->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=2c1f84f7-1a00-0000-3da6-7b0aec0d0000 pid=3564->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=78b346fe-1a00-0000-3da6-7b0afd0d0000 pid=3581 /usr/bin/bash guuid=a5d81efe-1a00-0000-3da6-7b0afb0d0000 pid=3579->guuid=78b346fe-1a00-0000-3da6-7b0afd0d0000 pid=3581 clone guuid=1aa01fff-1a00-0000-3da6-7b0a020e0000 pid=3586->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=70c00102-1b00-0000-3da6-7b0a0b0e0000 pid=3595->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e9e2fb06-1b00-0000-3da6-7b0a1b0e0000 pid=3611 /usr/bin/bash guuid=dcbfdd06-1b00-0000-3da6-7b0a190e0000 pid=3609->guuid=e9e2fb06-1b00-0000-3da6-7b0a1b0e0000 pid=3611 clone guuid=f1643a08-1b00-0000-3da6-7b0a200e0000 pid=3616->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=51dc060b-1b00-0000-3da6-7b0a270e0000 pid=3623->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=a5284410-1b00-0000-3da6-7b0a3c0e0000 pid=3644 /usr/bin/bash guuid=35ef2d10-1b00-0000-3da6-7b0a3a0e0000 pid=3642->guuid=a5284410-1b00-0000-3da6-7b0a3c0e0000 pid=3644 clone guuid=d5f9e410-1b00-0000-3da6-7b0a420e0000 pid=3650->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=20305b13-1b00-0000-3da6-7b0a4a0e0000 pid=3658->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=03e49c18-1b00-0000-3da6-7b0a550e0000 pid=3669 /usr/bin/bash guuid=91db7318-1b00-0000-3da6-7b0a540e0000 pid=3668->guuid=03e49c18-1b00-0000-3da6-7b0a550e0000 pid=3669 clone guuid=8e7f7119-1b00-0000-3da6-7b0a5b0e0000 pid=3675->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=21e53c1d-1b00-0000-3da6-7b0a650e0000 pid=3685->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=1e067821-1b00-0000-3da6-7b0a6e0e0000 pid=3694 /usr/bin/bash guuid=1e4c5221-1b00-0000-3da6-7b0a6d0e0000 pid=3693->guuid=1e067821-1b00-0000-3da6-7b0a6e0e0000 pid=3694 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-18 15:37:41 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c96ede852e613ff8a8d82fca5e0a9d65583effbb40e08cbcb5447141d33f7408

(this sample)

  
Delivery method
Distributed via web download

Comments