MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc7244d79a4c703f2f4c6c481e7af73a7266aa85d8c745041fa907c1914cad48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: cc7244d79a4c703f2f4c6c481e7af73a7266aa85d8c745041fa907c1914cad48
SHA3-384 hash: af294ead36faedcc211d701a49a28701f9ecb2271a5cd11d9674476cfb310e68736cadf632bd8af79efdb918531f8123
SHA1 hash: 7887ef2e1646defd6c3ed59f455bea8c83ce09f4
MD5 hash: e9ac4916cb230ca1970b6907642323f7
humanhash: purple-video-ink-fix
File name:ok
Download: download sample
File size:1'644 bytes
First seen:2026-06-17 06:26:04 UTC
Last seen:2026-06-18 04:39:21 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UE6pWPdGK6Crpk9Ni69NoX5pwRwRoD5WI65WejIsm96MlknD64L64J8YPPISx6Sm:WN7Ny5ukp4ejGlMDt5uY33Pu3MC8BG
TLSH T11B31218B98201A391712CDEEB3A73188710C46FF699BE7D4D88D0E9D87885D9B152F86
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/a79e1en/an/aua-wget
http://5.182.210.61/1e5164n/an/aua-wget
http://5.182.210.61/bc5646n/an/aua-wget
http://5.182.210.61/f96ad3n/an/aua-wget
http://5.182.210.61/492c83n/an/aua-wget
http://5.182.210.61/4aa3e0n/an/aua-wget
http://5.182.210.61/7d81c1n/an/aua-wget
http://5.182.210.61/0b9e47n/an/aua-wget
http://5.182.210.61/3a1cb2n/an/aua-wget
http://5.182.210.61/ccecean/an/aua-wget
http://5.182.210.61/c8a68an/an/aua-wget
http://5.182.210.61/ade2c6n/an/aua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-17T03:33:00Z UTC
Last seen:
2026-06-17T05:37:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=db068a1c-1700-0000-80d3-8cb4310d0000 pid=3377 /usr/bin/sudo guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385 /tmp/sample.bin guuid=db068a1c-1700-0000-80d3-8cb4310d0000 pid=3377->guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385 execve guuid=855cb41e-1700-0000-80d3-8cb43b0d0000 pid=3387 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=855cb41e-1700-0000-80d3-8cb43b0d0000 pid=3387 execve guuid=f2b3ad21-1700-0000-80d3-8cb4470d0000 pid=3399 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f2b3ad21-1700-0000-80d3-8cb4470d0000 pid=3399 execve guuid=ea3a8426-1700-0000-80d3-8cb45a0d0000 pid=3418 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=ea3a8426-1700-0000-80d3-8cb45a0d0000 pid=3418 execve guuid=f7aec426-1700-0000-80d3-8cb45c0d0000 pid=3420 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f7aec426-1700-0000-80d3-8cb45c0d0000 pid=3420 clone guuid=002bfe26-1700-0000-80d3-8cb45f0d0000 pid=3423 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=002bfe26-1700-0000-80d3-8cb45f0d0000 pid=3423 execve guuid=97ac3d27-1700-0000-80d3-8cb4610d0000 pid=3425 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=97ac3d27-1700-0000-80d3-8cb4610d0000 pid=3425 execve guuid=67097a27-1700-0000-80d3-8cb4630d0000 pid=3427 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=67097a27-1700-0000-80d3-8cb4630d0000 pid=3427 execve guuid=302bce29-1700-0000-80d3-8cb46d0d0000 pid=3437 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=302bce29-1700-0000-80d3-8cb46d0d0000 pid=3437 execve guuid=af6dfa2c-1700-0000-80d3-8cb47a0d0000 pid=3450 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=af6dfa2c-1700-0000-80d3-8cb47a0d0000 pid=3450 execve guuid=6c5a362d-1700-0000-80d3-8cb47c0d0000 pid=3452 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=6c5a362d-1700-0000-80d3-8cb47c0d0000 pid=3452 clone guuid=39b96b2d-1700-0000-80d3-8cb47f0d0000 pid=3455 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=39b96b2d-1700-0000-80d3-8cb47f0d0000 pid=3455 execve guuid=d157a92d-1700-0000-80d3-8cb4810d0000 pid=3457 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=d157a92d-1700-0000-80d3-8cb4810d0000 pid=3457 execve guuid=f963e62d-1700-0000-80d3-8cb4830d0000 pid=3459 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f963e62d-1700-0000-80d3-8cb4830d0000 pid=3459 execve guuid=89d43530-1700-0000-80d3-8cb48d0d0000 pid=3469 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=89d43530-1700-0000-80d3-8cb48d0d0000 pid=3469 execve guuid=ea259333-1700-0000-80d3-8cb49b0d0000 pid=3483 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=ea259333-1700-0000-80d3-8cb49b0d0000 pid=3483 execve guuid=2a0ee033-1700-0000-80d3-8cb49d0d0000 pid=3485 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=2a0ee033-1700-0000-80d3-8cb49d0d0000 pid=3485 clone guuid=2b132934-1700-0000-80d3-8cb4a00d0000 pid=3488 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=2b132934-1700-0000-80d3-8cb4a00d0000 pid=3488 execve guuid=036b7d34-1700-0000-80d3-8cb4a20d0000 pid=3490 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=036b7d34-1700-0000-80d3-8cb4a20d0000 pid=3490 execve guuid=b8a0bf34-1700-0000-80d3-8cb4a40d0000 pid=3492 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=b8a0bf34-1700-0000-80d3-8cb4a40d0000 pid=3492 execve guuid=e9d14337-1700-0000-80d3-8cb4ad0d0000 pid=3501 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=e9d14337-1700-0000-80d3-8cb4ad0d0000 pid=3501 execve guuid=f631e43a-1700-0000-80d3-8cb4b70d0000 pid=3511 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f631e43a-1700-0000-80d3-8cb4b70d0000 pid=3511 execve guuid=4f9c1a3b-1700-0000-80d3-8cb4b80d0000 pid=3512 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=4f9c1a3b-1700-0000-80d3-8cb4b80d0000 pid=3512 clone guuid=a3b1473b-1700-0000-80d3-8cb4ba0d0000 pid=3514 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=a3b1473b-1700-0000-80d3-8cb4ba0d0000 pid=3514 execve guuid=081a843b-1700-0000-80d3-8cb4bb0d0000 pid=3515 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=081a843b-1700-0000-80d3-8cb4bb0d0000 pid=3515 execve guuid=b4c6c03b-1700-0000-80d3-8cb4bc0d0000 pid=3516 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=b4c6c03b-1700-0000-80d3-8cb4bc0d0000 pid=3516 execve guuid=eb8b0f3e-1700-0000-80d3-8cb4c00d0000 pid=3520 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=eb8b0f3e-1700-0000-80d3-8cb4c00d0000 pid=3520 execve guuid=52825e41-1700-0000-80d3-8cb4cc0d0000 pid=3532 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=52825e41-1700-0000-80d3-8cb4cc0d0000 pid=3532 execve guuid=8e749c41-1700-0000-80d3-8cb4cd0d0000 pid=3533 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=8e749c41-1700-0000-80d3-8cb4cd0d0000 pid=3533 clone guuid=76c4c941-1700-0000-80d3-8cb4cf0d0000 pid=3535 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=76c4c941-1700-0000-80d3-8cb4cf0d0000 pid=3535 execve guuid=dd460642-1700-0000-80d3-8cb4d10d0000 pid=3537 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=dd460642-1700-0000-80d3-8cb4d10d0000 pid=3537 execve guuid=ccd74342-1700-0000-80d3-8cb4d30d0000 pid=3539 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=ccd74342-1700-0000-80d3-8cb4d30d0000 pid=3539 execve guuid=f66fae44-1700-0000-80d3-8cb4da0d0000 pid=3546 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f66fae44-1700-0000-80d3-8cb4da0d0000 pid=3546 execve guuid=eefe6348-1700-0000-80d3-8cb4e50d0000 pid=3557 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=eefe6348-1700-0000-80d3-8cb4e50d0000 pid=3557 execve guuid=e03cb948-1700-0000-80d3-8cb4e70d0000 pid=3559 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=e03cb948-1700-0000-80d3-8cb4e70d0000 pid=3559 clone guuid=2823f548-1700-0000-80d3-8cb4e90d0000 pid=3561 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=2823f548-1700-0000-80d3-8cb4e90d0000 pid=3561 execve guuid=a8574449-1700-0000-80d3-8cb4eb0d0000 pid=3563 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=a8574449-1700-0000-80d3-8cb4eb0d0000 pid=3563 execve guuid=8e369049-1700-0000-80d3-8cb4ed0d0000 pid=3565 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=8e369049-1700-0000-80d3-8cb4ed0d0000 pid=3565 execve guuid=7165124c-1700-0000-80d3-8cb4f20d0000 pid=3570 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=7165124c-1700-0000-80d3-8cb4f20d0000 pid=3570 execve guuid=c08c944f-1700-0000-80d3-8cb4000e0000 pid=3584 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=c08c944f-1700-0000-80d3-8cb4000e0000 pid=3584 execve guuid=ac19ed4f-1700-0000-80d3-8cb4020e0000 pid=3586 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=ac19ed4f-1700-0000-80d3-8cb4020e0000 pid=3586 clone guuid=66de2950-1700-0000-80d3-8cb4050e0000 pid=3589 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=66de2950-1700-0000-80d3-8cb4050e0000 pid=3589 execve guuid=075fa250-1700-0000-80d3-8cb4070e0000 pid=3591 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=075fa250-1700-0000-80d3-8cb4070e0000 pid=3591 execve guuid=909ae550-1700-0000-80d3-8cb4090e0000 pid=3593 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=909ae550-1700-0000-80d3-8cb4090e0000 pid=3593 execve guuid=659a2f53-1700-0000-80d3-8cb4120e0000 pid=3602 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=659a2f53-1700-0000-80d3-8cb4120e0000 pid=3602 execve guuid=55a82457-1700-0000-80d3-8cb41f0e0000 pid=3615 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=55a82457-1700-0000-80d3-8cb41f0e0000 pid=3615 execve guuid=8f989457-1700-0000-80d3-8cb4210e0000 pid=3617 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=8f989457-1700-0000-80d3-8cb4210e0000 pid=3617 clone guuid=c869da57-1700-0000-80d3-8cb4230e0000 pid=3619 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=c869da57-1700-0000-80d3-8cb4230e0000 pid=3619 execve guuid=712d2758-1700-0000-80d3-8cb4250e0000 pid=3621 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=712d2758-1700-0000-80d3-8cb4250e0000 pid=3621 execve guuid=c9ac6f58-1700-0000-80d3-8cb4270e0000 pid=3623 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=c9ac6f58-1700-0000-80d3-8cb4270e0000 pid=3623 execve guuid=8eaf175b-1700-0000-80d3-8cb42c0e0000 pid=3628 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=8eaf175b-1700-0000-80d3-8cb42c0e0000 pid=3628 execve guuid=ba6af55e-1700-0000-80d3-8cb42f0e0000 pid=3631 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=ba6af55e-1700-0000-80d3-8cb42f0e0000 pid=3631 execve guuid=33216d5f-1700-0000-80d3-8cb4310e0000 pid=3633 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=33216d5f-1700-0000-80d3-8cb4310e0000 pid=3633 clone guuid=4d41c25f-1700-0000-80d3-8cb4340e0000 pid=3636 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=4d41c25f-1700-0000-80d3-8cb4340e0000 pid=3636 execve guuid=f4022160-1700-0000-80d3-8cb4360e0000 pid=3638 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f4022160-1700-0000-80d3-8cb4360e0000 pid=3638 execve guuid=10aa7c60-1700-0000-80d3-8cb4380e0000 pid=3640 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=10aa7c60-1700-0000-80d3-8cb4380e0000 pid=3640 execve guuid=50566663-1700-0000-80d3-8cb4410e0000 pid=3649 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=50566663-1700-0000-80d3-8cb4410e0000 pid=3649 execve guuid=b0762767-1700-0000-80d3-8cb44b0e0000 pid=3659 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=b0762767-1700-0000-80d3-8cb44b0e0000 pid=3659 execve guuid=ef497567-1700-0000-80d3-8cb44d0e0000 pid=3661 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=ef497567-1700-0000-80d3-8cb44d0e0000 pid=3661 clone guuid=4f6cb967-1700-0000-80d3-8cb44f0e0000 pid=3663 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=4f6cb967-1700-0000-80d3-8cb44f0e0000 pid=3663 execve guuid=8a230968-1700-0000-80d3-8cb4520e0000 pid=3666 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=8a230968-1700-0000-80d3-8cb4520e0000 pid=3666 execve guuid=2ebc5068-1700-0000-80d3-8cb4530e0000 pid=3667 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=2ebc5068-1700-0000-80d3-8cb4530e0000 pid=3667 execve guuid=8effb26a-1700-0000-80d3-8cb45b0e0000 pid=3675 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=8effb26a-1700-0000-80d3-8cb45b0e0000 pid=3675 execve guuid=2bbb6971-1700-0000-80d3-8cb4650e0000 pid=3685 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=2bbb6971-1700-0000-80d3-8cb4650e0000 pid=3685 execve guuid=85a6b171-1700-0000-80d3-8cb4660e0000 pid=3686 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=85a6b171-1700-0000-80d3-8cb4660e0000 pid=3686 clone guuid=4f2d0572-1700-0000-80d3-8cb4680e0000 pid=3688 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=4f2d0572-1700-0000-80d3-8cb4680e0000 pid=3688 execve guuid=56b76572-1700-0000-80d3-8cb4690e0000 pid=3689 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=56b76572-1700-0000-80d3-8cb4690e0000 pid=3689 execve guuid=d753c272-1700-0000-80d3-8cb46c0e0000 pid=3692 /usr/bin/wget net send-data guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=d753c272-1700-0000-80d3-8cb46c0e0000 pid=3692 execve guuid=d9496375-1700-0000-80d3-8cb4790e0000 pid=3705 /usr/bin/curl net send-data write-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=d9496375-1700-0000-80d3-8cb4790e0000 pid=3705 execve guuid=03b60979-1700-0000-80d3-8cb4870e0000 pid=3719 /usr/bin/chmod guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=03b60979-1700-0000-80d3-8cb4870e0000 pid=3719 execve guuid=03275f79-1700-0000-80d3-8cb4890e0000 pid=3721 /usr/bin/bash guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=03275f79-1700-0000-80d3-8cb4890e0000 pid=3721 clone guuid=cf659879-1700-0000-80d3-8cb48c0e0000 pid=3724 /usr/bin/rm delete-file guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=cf659879-1700-0000-80d3-8cb48c0e0000 pid=3724 execve guuid=f228dd79-1700-0000-80d3-8cb48e0e0000 pid=3726 /usr/bin/rm guuid=2199681e-1700-0000-80d3-8cb4390d0000 pid=3385->guuid=f228dd79-1700-0000-80d3-8cb48e0e0000 pid=3726 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=855cb41e-1700-0000-80d3-8cb43b0d0000 pid=3387->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=f2b3ad21-1700-0000-80d3-8cb4470d0000 pid=3399->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=1207d926-1700-0000-80d3-8cb45d0d0000 pid=3421 /usr/bin/bash guuid=f7aec426-1700-0000-80d3-8cb45c0d0000 pid=3420->guuid=1207d926-1700-0000-80d3-8cb45d0d0000 pid=3421 clone guuid=67097a27-1700-0000-80d3-8cb4630d0000 pid=3427->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=302bce29-1700-0000-80d3-8cb46d0d0000 pid=3437->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=fb2a4d2d-1700-0000-80d3-8cb47d0d0000 pid=3453 /usr/bin/bash guuid=6c5a362d-1700-0000-80d3-8cb47c0d0000 pid=3452->guuid=fb2a4d2d-1700-0000-80d3-8cb47d0d0000 pid=3453 clone guuid=f963e62d-1700-0000-80d3-8cb4830d0000 pid=3459->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=89d43530-1700-0000-80d3-8cb48d0d0000 pid=3469->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ac43fd33-1700-0000-80d3-8cb49e0d0000 pid=3486 /usr/bin/bash guuid=2a0ee033-1700-0000-80d3-8cb49d0d0000 pid=3485->guuid=ac43fd33-1700-0000-80d3-8cb49e0d0000 pid=3486 clone guuid=b8a0bf34-1700-0000-80d3-8cb4a40d0000 pid=3492->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=e9d14337-1700-0000-80d3-8cb4ad0d0000 pid=3501->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=463f303b-1700-0000-80d3-8cb4b90d0000 pid=3513 /usr/bin/bash guuid=4f9c1a3b-1700-0000-80d3-8cb4b80d0000 pid=3512->guuid=463f303b-1700-0000-80d3-8cb4b90d0000 pid=3513 clone guuid=b4c6c03b-1700-0000-80d3-8cb4bc0d0000 pid=3516->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=eb8b0f3e-1700-0000-80d3-8cb4c00d0000 pid=3520->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ad85b041-1700-0000-80d3-8cb4ce0d0000 pid=3534 /usr/bin/bash guuid=8e749c41-1700-0000-80d3-8cb4cd0d0000 pid=3533->guuid=ad85b041-1700-0000-80d3-8cb4ce0d0000 pid=3534 clone guuid=ccd74342-1700-0000-80d3-8cb4d30d0000 pid=3539->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=f66fae44-1700-0000-80d3-8cb4da0d0000 pid=3546->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=589bd248-1700-0000-80d3-8cb4e80d0000 pid=3560 /usr/bin/bash guuid=e03cb948-1700-0000-80d3-8cb4e70d0000 pid=3559->guuid=589bd248-1700-0000-80d3-8cb4e80d0000 pid=3560 clone guuid=8e369049-1700-0000-80d3-8cb4ed0d0000 pid=3565->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=7165124c-1700-0000-80d3-8cb4f20d0000 pid=3570->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=83ea0350-1700-0000-80d3-8cb4030e0000 pid=3587 /usr/bin/bash guuid=ac19ed4f-1700-0000-80d3-8cb4020e0000 pid=3586->guuid=83ea0350-1700-0000-80d3-8cb4030e0000 pid=3587 clone guuid=909ae550-1700-0000-80d3-8cb4090e0000 pid=3593->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=659a2f53-1700-0000-80d3-8cb4120e0000 pid=3602->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e71fb957-1700-0000-80d3-8cb4220e0000 pid=3618 /usr/bin/bash guuid=8f989457-1700-0000-80d3-8cb4210e0000 pid=3617->guuid=e71fb957-1700-0000-80d3-8cb4220e0000 pid=3618 clone guuid=c9ac6f58-1700-0000-80d3-8cb4270e0000 pid=3623->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=8eaf175b-1700-0000-80d3-8cb42c0e0000 pid=3628->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=55b5905f-1700-0000-80d3-8cb4320e0000 pid=3634 /usr/bin/bash guuid=33216d5f-1700-0000-80d3-8cb4310e0000 pid=3633->guuid=55b5905f-1700-0000-80d3-8cb4320e0000 pid=3634 clone guuid=10aa7c60-1700-0000-80d3-8cb4380e0000 pid=3640->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=50566663-1700-0000-80d3-8cb4410e0000 pid=3649->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=18059567-1700-0000-80d3-8cb44e0e0000 pid=3662 /usr/bin/bash guuid=ef497567-1700-0000-80d3-8cb44d0e0000 pid=3661->guuid=18059567-1700-0000-80d3-8cb44e0e0000 pid=3662 clone guuid=2ebc5068-1700-0000-80d3-8cb4530e0000 pid=3667->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=8effb26a-1700-0000-80d3-8cb45b0e0000 pid=3675->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=90a3d371-1700-0000-80d3-8cb4670e0000 pid=3687 /usr/bin/bash guuid=85a6b171-1700-0000-80d3-8cb4660e0000 pid=3686->guuid=90a3d371-1700-0000-80d3-8cb4670e0000 pid=3687 clone guuid=d753c272-1700-0000-80d3-8cb46c0e0000 pid=3692->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=d9496375-1700-0000-80d3-8cb4790e0000 pid=3705->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=90b37879-1700-0000-80d3-8cb48b0e0000 pid=3723 /usr/bin/bash guuid=03275f79-1700-0000-80d3-8cb4890e0000 pid=3721->guuid=90b37879-1700-0000-80d3-8cb48b0e0000 pid=3723 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-17 06:26:40 UTC
File Type:
Text (Shell)
AV detection:
9 of 35 (25.71%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh cc7244d79a4c703f2f4c6c481e7af73a7266aa85d8c745041fa907c1914cad48

(this sample)

  
Delivery method
Distributed via web download

Comments