MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf00ec5f2c68c86558bd874e252b80f287bb20e4a3ec96b3fbcaf96fb743074f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: cf00ec5f2c68c86558bd874e252b80f287bb20e4a3ec96b3fbcaf96fb743074f
SHA3-384 hash: 442012f4e261c03ce02f2cc26ba294703b525454eb2c22114fd830d525b0323ea35cf777e957b549b62f925eb65742c8
SHA1 hash: c0fd30fa47ab3a95c04c3671dcde1b88100e14a8
MD5 hash: 649c1b1d793d94703903d2fbde9f9ae0
humanhash: muppet-friend-montana-bulldog
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-10 13:58:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkaFXIaNWmUFISYhvIpo0zEIucIOeV1auD:kXCKysE2hi0ziQvZohaFXnoFhC11EgT7
TLSH T14D016FDDC002EB604195E8AD32975290B820C3CB1A464BB87FDD043D9B69B58F055F98
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/9lQtn/an/aelf ua-wget
http://188.132.232.81/ltoin/an/aelf ua-wget
http://188.132.232.81/Myvn/an/aelf ua-wget
http://188.132.232.81/9VPVn/an/aelf ua-wget
http://188.132.232.81/pibn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=6dbf79a1-1a00-0000-0478-d192ee090000 pid=2542 /usr/bin/sudo guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549 /tmp/sample.bin write-file guuid=6dbf79a1-1a00-0000-0478-d192ee090000 pid=2542->guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549 execve guuid=d13b1ea4-1a00-0000-0478-d192f7090000 pid=2551 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=d13b1ea4-1a00-0000-0478-d192f7090000 pid=2551 execve guuid=3c6c38a5-1a00-0000-0478-d192fa090000 pid=2554 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3c6c38a5-1a00-0000-0478-d192fa090000 pid=2554 execve guuid=3862d0a5-1a00-0000-0478-d192fb090000 pid=2555 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3862d0a5-1a00-0000-0478-d192fb090000 pid=2555 execve guuid=b66659a6-1a00-0000-0478-d192fe090000 pid=2558 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b66659a6-1a00-0000-0478-d192fe090000 pid=2558 execve guuid=e4e8fba6-1a00-0000-0478-d192010a0000 pid=2561 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e4e8fba6-1a00-0000-0478-d192010a0000 pid=2561 execve guuid=45ca7fa7-1a00-0000-0478-d192030a0000 pid=2563 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=45ca7fa7-1a00-0000-0478-d192030a0000 pid=2563 execve guuid=379412a8-1a00-0000-0478-d192050a0000 pid=2565 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=379412a8-1a00-0000-0478-d192050a0000 pid=2565 execve guuid=451c97a8-1a00-0000-0478-d192070a0000 pid=2567 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=451c97a8-1a00-0000-0478-d192070a0000 pid=2567 execve guuid=70b548a9-1a00-0000-0478-d1920a0a0000 pid=2570 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=70b548a9-1a00-0000-0478-d1920a0a0000 pid=2570 execve guuid=63a2f9a9-1a00-0000-0478-d1920d0a0000 pid=2573 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=63a2f9a9-1a00-0000-0478-d1920d0a0000 pid=2573 execve guuid=256bdcaa-1a00-0000-0478-d1920f0a0000 pid=2575 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=256bdcaa-1a00-0000-0478-d1920f0a0000 pid=2575 execve guuid=43939dab-1a00-0000-0478-d192120a0000 pid=2578 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=43939dab-1a00-0000-0478-d192120a0000 pid=2578 execve guuid=073a22ac-1a00-0000-0478-d192150a0000 pid=2581 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=073a22ac-1a00-0000-0478-d192150a0000 pid=2581 execve guuid=24e8c2ac-1a00-0000-0478-d192170a0000 pid=2583 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=24e8c2ac-1a00-0000-0478-d192170a0000 pid=2583 execve guuid=ab6a42ad-1a00-0000-0478-d1921a0a0000 pid=2586 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=ab6a42ad-1a00-0000-0478-d1921a0a0000 pid=2586 execve guuid=d223f9ad-1a00-0000-0478-d1921c0a0000 pid=2588 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=d223f9ad-1a00-0000-0478-d1921c0a0000 pid=2588 execve guuid=e6e571ae-1a00-0000-0478-d1921f0a0000 pid=2591 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e6e571ae-1a00-0000-0478-d1921f0a0000 pid=2591 execve guuid=bf6702af-1a00-0000-0478-d192210a0000 pid=2593 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=bf6702af-1a00-0000-0478-d192210a0000 pid=2593 execve guuid=507694af-1a00-0000-0478-d192240a0000 pid=2596 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=507694af-1a00-0000-0478-d192240a0000 pid=2596 execve guuid=cb1918b0-1a00-0000-0478-d192270a0000 pid=2599 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=cb1918b0-1a00-0000-0478-d192270a0000 pid=2599 execve guuid=5b6f9fb0-1a00-0000-0478-d192290a0000 pid=2601 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=5b6f9fb0-1a00-0000-0478-d192290a0000 pid=2601 execve guuid=4a2234b1-1a00-0000-0478-d1922c0a0000 pid=2604 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=4a2234b1-1a00-0000-0478-d1922c0a0000 pid=2604 execve guuid=e162d7b1-1a00-0000-0478-d1922e0a0000 pid=2606 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e162d7b1-1a00-0000-0478-d1922e0a0000 pid=2606 execve guuid=b70c48b2-1a00-0000-0478-d192300a0000 pid=2608 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b70c48b2-1a00-0000-0478-d192300a0000 pid=2608 execve guuid=5a75d6b2-1a00-0000-0478-d192320a0000 pid=2610 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=5a75d6b2-1a00-0000-0478-d192320a0000 pid=2610 execve guuid=78ed7fb3-1a00-0000-0478-d192350a0000 pid=2613 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=78ed7fb3-1a00-0000-0478-d192350a0000 pid=2613 execve guuid=0753f6b3-1a00-0000-0478-d192370a0000 pid=2615 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=0753f6b3-1a00-0000-0478-d192370a0000 pid=2615 execve guuid=8a958cb4-1a00-0000-0478-d1923a0a0000 pid=2618 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=8a958cb4-1a00-0000-0478-d1923a0a0000 pid=2618 execve guuid=f02b09b5-1a00-0000-0478-d1923d0a0000 pid=2621 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=f02b09b5-1a00-0000-0478-d1923d0a0000 pid=2621 execve guuid=4bea76b5-1a00-0000-0478-d1923f0a0000 pid=2623 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=4bea76b5-1a00-0000-0478-d1923f0a0000 pid=2623 execve guuid=af24ecb5-1a00-0000-0478-d192410a0000 pid=2625 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=af24ecb5-1a00-0000-0478-d192410a0000 pid=2625 execve guuid=822460b6-1a00-0000-0478-d192430a0000 pid=2627 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=822460b6-1a00-0000-0478-d192430a0000 pid=2627 execve guuid=2c7bd2b6-1a00-0000-0478-d192450a0000 pid=2629 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=2c7bd2b6-1a00-0000-0478-d192450a0000 pid=2629 execve guuid=21cc64b7-1a00-0000-0478-d192470a0000 pid=2631 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=21cc64b7-1a00-0000-0478-d192470a0000 pid=2631 execve guuid=47b8e4b7-1a00-0000-0478-d192490a0000 pid=2633 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=47b8e4b7-1a00-0000-0478-d192490a0000 pid=2633 execve guuid=a1be63b8-1a00-0000-0478-d1924c0a0000 pid=2636 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=a1be63b8-1a00-0000-0478-d1924c0a0000 pid=2636 execve guuid=409fdeb8-1a00-0000-0478-d1924f0a0000 pid=2639 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=409fdeb8-1a00-0000-0478-d1924f0a0000 pid=2639 execve guuid=6f1e52b9-1a00-0000-0478-d192510a0000 pid=2641 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=6f1e52b9-1a00-0000-0478-d192510a0000 pid=2641 execve guuid=4c53dab9-1a00-0000-0478-d192530a0000 pid=2643 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=4c53dab9-1a00-0000-0478-d192530a0000 pid=2643 execve guuid=27485fba-1a00-0000-0478-d192560a0000 pid=2646 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=27485fba-1a00-0000-0478-d192560a0000 pid=2646 execve guuid=e6e1dfba-1a00-0000-0478-d192580a0000 pid=2648 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e6e1dfba-1a00-0000-0478-d192580a0000 pid=2648 execve guuid=11d880bb-1a00-0000-0478-d1925b0a0000 pid=2651 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=11d880bb-1a00-0000-0478-d1925b0a0000 pid=2651 execve guuid=9b402abc-1a00-0000-0478-d1925e0a0000 pid=2654 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9b402abc-1a00-0000-0478-d1925e0a0000 pid=2654 execve guuid=1384ccbc-1a00-0000-0478-d192610a0000 pid=2657 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1384ccbc-1a00-0000-0478-d192610a0000 pid=2657 execve guuid=ac055abd-1a00-0000-0478-d192640a0000 pid=2660 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=ac055abd-1a00-0000-0478-d192640a0000 pid=2660 execve guuid=3db8e1bd-1a00-0000-0478-d192670a0000 pid=2663 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3db8e1bd-1a00-0000-0478-d192670a0000 pid=2663 execve guuid=452655be-1a00-0000-0478-d192690a0000 pid=2665 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=452655be-1a00-0000-0478-d192690a0000 pid=2665 execve guuid=487dd2be-1a00-0000-0478-d1926c0a0000 pid=2668 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=487dd2be-1a00-0000-0478-d1926c0a0000 pid=2668 execve guuid=3e9c47bf-1a00-0000-0478-d1926e0a0000 pid=2670 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3e9c47bf-1a00-0000-0478-d1926e0a0000 pid=2670 execve guuid=9ecbccbf-1a00-0000-0478-d192700a0000 pid=2672 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9ecbccbf-1a00-0000-0478-d192700a0000 pid=2672 execve guuid=264167c0-1a00-0000-0478-d192730a0000 pid=2675 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=264167c0-1a00-0000-0478-d192730a0000 pid=2675 execve guuid=664fddc0-1a00-0000-0478-d192750a0000 pid=2677 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=664fddc0-1a00-0000-0478-d192750a0000 pid=2677 execve guuid=7a02b2c1-1a00-0000-0478-d192790a0000 pid=2681 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=7a02b2c1-1a00-0000-0478-d192790a0000 pid=2681 execve guuid=83c723c2-1a00-0000-0478-d1927b0a0000 pid=2683 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=83c723c2-1a00-0000-0478-d1927b0a0000 pid=2683 execve guuid=2ff5b6c2-1a00-0000-0478-d1927e0a0000 pid=2686 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=2ff5b6c2-1a00-0000-0478-d1927e0a0000 pid=2686 execve guuid=eb043ec3-1a00-0000-0478-d192800a0000 pid=2688 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=eb043ec3-1a00-0000-0478-d192800a0000 pid=2688 execve guuid=9fa4acc3-1a00-0000-0478-d192820a0000 pid=2690 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9fa4acc3-1a00-0000-0478-d192820a0000 pid=2690 execve guuid=3c7330c4-1a00-0000-0478-d192840a0000 pid=2692 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3c7330c4-1a00-0000-0478-d192840a0000 pid=2692 execve guuid=be13c5c4-1a00-0000-0478-d192870a0000 pid=2695 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=be13c5c4-1a00-0000-0478-d192870a0000 pid=2695 execve guuid=c5ad2dc5-1a00-0000-0478-d192890a0000 pid=2697 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=c5ad2dc5-1a00-0000-0478-d192890a0000 pid=2697 execve guuid=1c5de1c5-1a00-0000-0478-d1928c0a0000 pid=2700 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1c5de1c5-1a00-0000-0478-d1928c0a0000 pid=2700 execve guuid=b68a49c6-1a00-0000-0478-d1928e0a0000 pid=2702 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b68a49c6-1a00-0000-0478-d1928e0a0000 pid=2702 execve guuid=6a85bdc6-1a00-0000-0478-d192900a0000 pid=2704 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=6a85bdc6-1a00-0000-0478-d192900a0000 pid=2704 execve guuid=85a721c7-1a00-0000-0478-d192920a0000 pid=2706 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=85a721c7-1a00-0000-0478-d192920a0000 pid=2706 execve guuid=b42b84c7-1a00-0000-0478-d192940a0000 pid=2708 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b42b84c7-1a00-0000-0478-d192940a0000 pid=2708 execve guuid=8a37e8c7-1a00-0000-0478-d192960a0000 pid=2710 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=8a37e8c7-1a00-0000-0478-d192960a0000 pid=2710 execve guuid=b0304ac8-1a00-0000-0478-d192980a0000 pid=2712 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b0304ac8-1a00-0000-0478-d192980a0000 pid=2712 execve guuid=9064e0c8-1a00-0000-0478-d1929a0a0000 pid=2714 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9064e0c8-1a00-0000-0478-d1929a0a0000 pid=2714 execve guuid=88817bc9-1a00-0000-0478-d1929c0a0000 pid=2716 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=88817bc9-1a00-0000-0478-d1929c0a0000 pid=2716 execve guuid=dbd30aca-1a00-0000-0478-d1929e0a0000 pid=2718 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=dbd30aca-1a00-0000-0478-d1929e0a0000 pid=2718 execve guuid=541ea9ca-1a00-0000-0478-d192a00a0000 pid=2720 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=541ea9ca-1a00-0000-0478-d192a00a0000 pid=2720 execve guuid=4bf248cb-1a00-0000-0478-d192a30a0000 pid=2723 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=4bf248cb-1a00-0000-0478-d192a30a0000 pid=2723 execve guuid=16c2e1cb-1a00-0000-0478-d192a60a0000 pid=2726 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=16c2e1cb-1a00-0000-0478-d192a60a0000 pid=2726 execve guuid=c99b76cc-1a00-0000-0478-d192a90a0000 pid=2729 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=c99b76cc-1a00-0000-0478-d192a90a0000 pid=2729 execve guuid=e8aed9cc-1a00-0000-0478-d192ab0a0000 pid=2731 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e8aed9cc-1a00-0000-0478-d192ab0a0000 pid=2731 execve guuid=55443bcd-1a00-0000-0478-d192ad0a0000 pid=2733 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=55443bcd-1a00-0000-0478-d192ad0a0000 pid=2733 execve guuid=1015a8cd-1a00-0000-0478-d192af0a0000 pid=2735 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1015a8cd-1a00-0000-0478-d192af0a0000 pid=2735 execve guuid=e5390fce-1a00-0000-0478-d192b10a0000 pid=2737 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e5390fce-1a00-0000-0478-d192b10a0000 pid=2737 execve guuid=e79581ce-1a00-0000-0478-d192b20a0000 pid=2738 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e79581ce-1a00-0000-0478-d192b20a0000 pid=2738 execve guuid=5824e1ce-1a00-0000-0478-d192b50a0000 pid=2741 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=5824e1ce-1a00-0000-0478-d192b50a0000 pid=2741 execve guuid=c6c362cf-1a00-0000-0478-d192b70a0000 pid=2743 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=c6c362cf-1a00-0000-0478-d192b70a0000 pid=2743 execve guuid=a536c0cf-1a00-0000-0478-d192b90a0000 pid=2745 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=a536c0cf-1a00-0000-0478-d192b90a0000 pid=2745 execve guuid=cdee38d0-1a00-0000-0478-d192bb0a0000 pid=2747 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=cdee38d0-1a00-0000-0478-d192bb0a0000 pid=2747 execve guuid=be6297d0-1a00-0000-0478-d192bd0a0000 pid=2749 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=be6297d0-1a00-0000-0478-d192bd0a0000 pid=2749 execve guuid=3889f8d0-1a00-0000-0478-d192bf0a0000 pid=2751 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3889f8d0-1a00-0000-0478-d192bf0a0000 pid=2751 execve guuid=402759d1-1a00-0000-0478-d192c10a0000 pid=2753 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=402759d1-1a00-0000-0478-d192c10a0000 pid=2753 execve guuid=cc18bad1-1a00-0000-0478-d192c30a0000 pid=2755 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=cc18bad1-1a00-0000-0478-d192c30a0000 pid=2755 execve guuid=0d1517d2-1a00-0000-0478-d192c50a0000 pid=2757 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=0d1517d2-1a00-0000-0478-d192c50a0000 pid=2757 execve guuid=759271d2-1a00-0000-0478-d192c70a0000 pid=2759 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=759271d2-1a00-0000-0478-d192c70a0000 pid=2759 execve guuid=1c0207d3-1a00-0000-0478-d192ca0a0000 pid=2762 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1c0207d3-1a00-0000-0478-d192ca0a0000 pid=2762 execve guuid=aee3afd3-1a00-0000-0478-d192cc0a0000 pid=2764 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=aee3afd3-1a00-0000-0478-d192cc0a0000 pid=2764 execve guuid=e60e63d4-1a00-0000-0478-d192ce0a0000 pid=2766 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e60e63d4-1a00-0000-0478-d192ce0a0000 pid=2766 execve guuid=05f6f6d4-1a00-0000-0478-d192d00a0000 pid=2768 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=05f6f6d4-1a00-0000-0478-d192d00a0000 pid=2768 execve guuid=317a94d5-1a00-0000-0478-d192d30a0000 pid=2771 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=317a94d5-1a00-0000-0478-d192d30a0000 pid=2771 execve guuid=15c829d6-1a00-0000-0478-d192d70a0000 pid=2775 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=15c829d6-1a00-0000-0478-d192d70a0000 pid=2775 execve guuid=83e590d6-1a00-0000-0478-d192d90a0000 pid=2777 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=83e590d6-1a00-0000-0478-d192d90a0000 pid=2777 execve guuid=a27205d7-1a00-0000-0478-d192db0a0000 pid=2779 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=a27205d7-1a00-0000-0478-d192db0a0000 pid=2779 execve guuid=98f480d7-1a00-0000-0478-d192dd0a0000 pid=2781 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=98f480d7-1a00-0000-0478-d192dd0a0000 pid=2781 execve guuid=662809d8-1a00-0000-0478-d192df0a0000 pid=2783 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=662809d8-1a00-0000-0478-d192df0a0000 pid=2783 execve guuid=e271bad8-1a00-0000-0478-d192e20a0000 pid=2786 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e271bad8-1a00-0000-0478-d192e20a0000 pid=2786 execve guuid=1f954dd9-1a00-0000-0478-d192e40a0000 pid=2788 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1f954dd9-1a00-0000-0478-d192e40a0000 pid=2788 execve guuid=3639c6d9-1a00-0000-0478-d192e70a0000 pid=2791 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=3639c6d9-1a00-0000-0478-d192e70a0000 pid=2791 execve guuid=c8c244da-1a00-0000-0478-d192ea0a0000 pid=2794 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=c8c244da-1a00-0000-0478-d192ea0a0000 pid=2794 execve guuid=41daddda-1a00-0000-0478-d192ed0a0000 pid=2797 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=41daddda-1a00-0000-0478-d192ed0a0000 pid=2797 execve guuid=28974fdb-1a00-0000-0478-d192ef0a0000 pid=2799 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=28974fdb-1a00-0000-0478-d192ef0a0000 pid=2799 execve guuid=f683c0db-1a00-0000-0478-d192f10a0000 pid=2801 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=f683c0db-1a00-0000-0478-d192f10a0000 pid=2801 execve guuid=b2184fdc-1a00-0000-0478-d192f40a0000 pid=2804 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b2184fdc-1a00-0000-0478-d192f40a0000 pid=2804 execve guuid=9a31bfdc-1a00-0000-0478-d192f60a0000 pid=2806 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9a31bfdc-1a00-0000-0478-d192f60a0000 pid=2806 execve guuid=c5674cdd-1a00-0000-0478-d192f80a0000 pid=2808 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=c5674cdd-1a00-0000-0478-d192f80a0000 pid=2808 execve guuid=c4dbecdd-1a00-0000-0478-d192fb0a0000 pid=2811 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=c4dbecdd-1a00-0000-0478-d192fb0a0000 pid=2811 execve guuid=88bf8dde-1a00-0000-0478-d192fe0a0000 pid=2814 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=88bf8dde-1a00-0000-0478-d192fe0a0000 pid=2814 execve guuid=4d20fcde-1a00-0000-0478-d192000b0000 pid=2816 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=4d20fcde-1a00-0000-0478-d192000b0000 pid=2816 execve guuid=9208b0df-1a00-0000-0478-d192040b0000 pid=2820 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9208b0df-1a00-0000-0478-d192040b0000 pid=2820 execve guuid=65d336e0-1a00-0000-0478-d192060b0000 pid=2822 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=65d336e0-1a00-0000-0478-d192060b0000 pid=2822 execve guuid=bf63b6e0-1a00-0000-0478-d192080b0000 pid=2824 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=bf63b6e0-1a00-0000-0478-d192080b0000 pid=2824 execve guuid=34f633e1-1a00-0000-0478-d1920b0b0000 pid=2827 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=34f633e1-1a00-0000-0478-d1920b0b0000 pid=2827 execve guuid=7528a8e1-1a00-0000-0478-d1920d0b0000 pid=2829 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=7528a8e1-1a00-0000-0478-d1920d0b0000 pid=2829 execve guuid=34ab16e2-1a00-0000-0478-d192100b0000 pid=2832 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=34ab16e2-1a00-0000-0478-d192100b0000 pid=2832 execve guuid=e6e59ce2-1a00-0000-0478-d192130b0000 pid=2835 /usr/bin/ls guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e6e59ce2-1a00-0000-0478-d192130b0000 pid=2835 execve guuid=9ed415e3-1a00-0000-0478-d192150b0000 pid=2837 /usr/bin/rm guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9ed415e3-1a00-0000-0478-d192150b0000 pid=2837 execve guuid=6d0f57e3-1a00-0000-0478-d192170b0000 pid=2839 /usr/bin/wget net send-data write-file guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=6d0f57e3-1a00-0000-0478-d192170b0000 pid=2839 execve guuid=48f15ced-1a00-0000-0478-d1922b0b0000 pid=2859 /usr/bin/chmod guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=48f15ced-1a00-0000-0478-d1922b0b0000 pid=2859 execve guuid=e3cadfed-1a00-0000-0478-d1922c0b0000 pid=2860 /tmp/9lQt guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e3cadfed-1a00-0000-0478-d1922c0b0000 pid=2860 execve guuid=fd01ceef-1a00-0000-0478-d192340b0000 pid=2868 /usr/bin/rm guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=fd01ceef-1a00-0000-0478-d192340b0000 pid=2868 execve guuid=d20409f0-1a00-0000-0478-d192350b0000 pid=2869 /usr/bin/wget net send-data write-file guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=d20409f0-1a00-0000-0478-d192350b0000 pid=2869 execve guuid=d5cc8cf6-1a00-0000-0478-d192440b0000 pid=2884 /usr/bin/chmod guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=d5cc8cf6-1a00-0000-0478-d192440b0000 pid=2884 execve guuid=1811e3f6-1a00-0000-0478-d192450b0000 pid=2885 /tmp/ltoi guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1811e3f6-1a00-0000-0478-d192450b0000 pid=2885 execve guuid=e0def7f7-1a00-0000-0478-d192470b0000 pid=2887 /usr/bin/rm guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=e0def7f7-1a00-0000-0478-d192470b0000 pid=2887 execve guuid=b65744f8-1a00-0000-0478-d192480b0000 pid=2888 /usr/bin/wget net send-data write-file guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=b65744f8-1a00-0000-0478-d192480b0000 pid=2888 execve guuid=f94a1443-1b00-0000-0478-d1929c0b0000 pid=2972 /usr/bin/chmod guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=f94a1443-1b00-0000-0478-d1929c0b0000 pid=2972 execve guuid=474a8c43-1b00-0000-0478-d1929e0b0000 pid=2974 /tmp/Myv guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=474a8c43-1b00-0000-0478-d1929e0b0000 pid=2974 execve guuid=9289d544-1b00-0000-0478-d192a00b0000 pid=2976 /usr/bin/rm guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9289d544-1b00-0000-0478-d192a00b0000 pid=2976 execve guuid=1dbe4a45-1b00-0000-0478-d192a10b0000 pid=2977 /usr/bin/wget net send-data write-file guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=1dbe4a45-1b00-0000-0478-d192a10b0000 pid=2977 execve guuid=9f48af96-1b00-0000-0478-d1922d0c0000 pid=3117 /usr/bin/chmod guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=9f48af96-1b00-0000-0478-d1922d0c0000 pid=3117 execve guuid=8a58ee96-1b00-0000-0478-d1922e0c0000 pid=3118 /tmp/9VPV guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=8a58ee96-1b00-0000-0478-d1922e0c0000 pid=3118 execve guuid=2a6abf98-1b00-0000-0478-d192340c0000 pid=3124 /usr/bin/rm guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=2a6abf98-1b00-0000-0478-d192340c0000 pid=3124 execve guuid=8e821a99-1b00-0000-0478-d192350c0000 pid=3125 /usr/bin/wget net send-data write-file guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=8e821a99-1b00-0000-0478-d192350c0000 pid=3125 execve guuid=abaf4ca1-1b00-0000-0478-d192440c0000 pid=3140 /usr/bin/chmod guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=abaf4ca1-1b00-0000-0478-d192440c0000 pid=3140 execve guuid=8eba96a1-1b00-0000-0478-d192450c0000 pid=3141 /tmp/pib guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=8eba96a1-1b00-0000-0478-d192450c0000 pid=3141 execve guuid=bf1abda2-1b00-0000-0478-d1924a0c0000 pid=3146 /usr/bin/rm delete-file guuid=9a889ea3-1a00-0000-0478-d192f5090000 pid=2549->guuid=bf1abda2-1b00-0000-0478-d1924a0c0000 pid=3146 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=6d0f57e3-1a00-0000-0478-d192170b0000 pid=2839->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=d20409f0-1a00-0000-0478-d192350b0000 pid=2869->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=b65744f8-1a00-0000-0478-d192480b0000 pid=2888->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=1dbe4a45-1b00-0000-0478-d192a10b0000 pid=2977->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=8e821a99-1b00-0000-0478-d192350c0000 pid=3125->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh cf00ec5f2c68c86558bd874e252b80f287bb20e4a3ec96b3fbcaf96fb743074f

(this sample)

  
Delivery method
Distributed via web download

Comments