MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d58fea3df011e3434ac8d727d933e9220cabaf805ea5de89f475f9f1e84dbfd5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d58fea3df011e3434ac8d727d933e9220cabaf805ea5de89f475f9f1e84dbfd5
SHA3-384 hash: be17b6f6510c1178369f790e1ea63e705c2e366cd2e75d61a4af0fe7e31aba42f8eccb4baa5476afc4f75a6b0cb00f43
SHA1 hash: 9c64107dde991e41d3140a0b9cebb79b8c483228
MD5 hash: 3a4e29fecbc834c2192a51f2c10d66b3
humanhash: social-georgia-ceiling-fish
File name:lil
Download: download sample
File size:851 bytes
First seen:2026-06-05 04:51:23 UTC
Last seen:2026-06-05 12:29:09 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZoha1+fNb6mXxeEOLdjWeX:e9Qp+Ms1seeYEcj7X
TLSH T10D018CDFC106DB6091C5E86D22E76244B42183CB29418FB5BE6C94BEABA9B0C7075E85
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/azAJn/an/aelf ua-wget
http://188.132.232.81/kAqyn/an/aelf ua-wget
http://188.132.232.81/XmgGn/an/aelf ua-wget
http://188.132.232.81/19ion/an/aelf ua-wget
http://188.132.232.81/f9f5n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-05T01:57:00Z UTC
Last seen:
2026-06-06T22:07:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=107f2508-1700-0000-6080-74388c0d0000 pid=3468 /usr/bin/sudo guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475 /tmp/sample.bin write-file guuid=107f2508-1700-0000-6080-74388c0d0000 pid=3468->guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475 execve guuid=f13d200b-1700-0000-6080-7438950d0000 pid=3477 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=f13d200b-1700-0000-6080-7438950d0000 pid=3477 execve guuid=7364aa0b-1700-0000-6080-7438970d0000 pid=3479 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7364aa0b-1700-0000-6080-7438970d0000 pid=3479 execve guuid=cb7a2d0c-1700-0000-6080-74389a0d0000 pid=3482 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=cb7a2d0c-1700-0000-6080-74389a0d0000 pid=3482 execve guuid=a6b0a70c-1700-0000-6080-74389c0d0000 pid=3484 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=a6b0a70c-1700-0000-6080-74389c0d0000 pid=3484 execve guuid=06e62b0d-1700-0000-6080-74389f0d0000 pid=3487 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=06e62b0d-1700-0000-6080-74389f0d0000 pid=3487 execve guuid=4b74b10d-1700-0000-6080-7438a40d0000 pid=3492 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=4b74b10d-1700-0000-6080-7438a40d0000 pid=3492 execve guuid=7ee0750e-1700-0000-6080-7438a50d0000 pid=3493 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7ee0750e-1700-0000-6080-7438a50d0000 pid=3493 execve guuid=41a80c0f-1700-0000-6080-7438a60d0000 pid=3494 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=41a80c0f-1700-0000-6080-7438a60d0000 pid=3494 execve guuid=d574960f-1700-0000-6080-7438a70d0000 pid=3495 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=d574960f-1700-0000-6080-7438a70d0000 pid=3495 execve guuid=682e2610-1700-0000-6080-7438a80d0000 pid=3496 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=682e2610-1700-0000-6080-7438a80d0000 pid=3496 execve guuid=7e9eb710-1700-0000-6080-7438a90d0000 pid=3497 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7e9eb710-1700-0000-6080-7438a90d0000 pid=3497 execve guuid=9d605611-1700-0000-6080-7438aa0d0000 pid=3498 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=9d605611-1700-0000-6080-7438aa0d0000 pid=3498 execve guuid=d5f6ee11-1700-0000-6080-7438ab0d0000 pid=3499 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=d5f6ee11-1700-0000-6080-7438ab0d0000 pid=3499 execve guuid=62f97612-1700-0000-6080-7438ac0d0000 pid=3500 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=62f97612-1700-0000-6080-7438ac0d0000 pid=3500 execve guuid=2b8efc12-1700-0000-6080-7438ad0d0000 pid=3501 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=2b8efc12-1700-0000-6080-7438ad0d0000 pid=3501 execve guuid=02f48513-1700-0000-6080-7438ae0d0000 pid=3502 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=02f48513-1700-0000-6080-7438ae0d0000 pid=3502 execve guuid=1a2a0814-1700-0000-6080-7438af0d0000 pid=3503 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=1a2a0814-1700-0000-6080-7438af0d0000 pid=3503 execve guuid=b5538814-1700-0000-6080-7438b00d0000 pid=3504 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=b5538814-1700-0000-6080-7438b00d0000 pid=3504 execve guuid=b3710615-1700-0000-6080-7438b10d0000 pid=3505 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=b3710615-1700-0000-6080-7438b10d0000 pid=3505 execve guuid=2cc69915-1700-0000-6080-7438b50d0000 pid=3509 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=2cc69915-1700-0000-6080-7438b50d0000 pid=3509 execve guuid=c7606e16-1700-0000-6080-7438b80d0000 pid=3512 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=c7606e16-1700-0000-6080-7438b80d0000 pid=3512 execve guuid=3b5ee716-1700-0000-6080-7438ba0d0000 pid=3514 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=3b5ee716-1700-0000-6080-7438ba0d0000 pid=3514 execve guuid=7c5b4c17-1700-0000-6080-7438bc0d0000 pid=3516 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7c5b4c17-1700-0000-6080-7438bc0d0000 pid=3516 execve guuid=4942b617-1700-0000-6080-7438bf0d0000 pid=3519 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=4942b617-1700-0000-6080-7438bf0d0000 pid=3519 execve guuid=e9781c18-1700-0000-6080-7438c10d0000 pid=3521 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=e9781c18-1700-0000-6080-7438c10d0000 pid=3521 execve guuid=9cb17a18-1700-0000-6080-7438c40d0000 pid=3524 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=9cb17a18-1700-0000-6080-7438c40d0000 pid=3524 execve guuid=0a50e018-1700-0000-6080-7438c60d0000 pid=3526 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=0a50e018-1700-0000-6080-7438c60d0000 pid=3526 execve guuid=782d4519-1700-0000-6080-7438c70d0000 pid=3527 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=782d4519-1700-0000-6080-7438c70d0000 pid=3527 execve guuid=02aab019-1700-0000-6080-7438c90d0000 pid=3529 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=02aab019-1700-0000-6080-7438c90d0000 pid=3529 execve guuid=e0fd171a-1700-0000-6080-7438cb0d0000 pid=3531 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=e0fd171a-1700-0000-6080-7438cb0d0000 pid=3531 execve guuid=a5ba801a-1700-0000-6080-7438ce0d0000 pid=3534 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=a5ba801a-1700-0000-6080-7438ce0d0000 pid=3534 execve guuid=5964e21a-1700-0000-6080-7438d00d0000 pid=3536 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=5964e21a-1700-0000-6080-7438d00d0000 pid=3536 execve guuid=0edd421b-1700-0000-6080-7438d30d0000 pid=3539 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=0edd421b-1700-0000-6080-7438d30d0000 pid=3539 execve guuid=a3e39e1b-1700-0000-6080-7438d40d0000 pid=3540 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=a3e39e1b-1700-0000-6080-7438d40d0000 pid=3540 execve guuid=52c5fb1b-1700-0000-6080-7438d60d0000 pid=3542 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=52c5fb1b-1700-0000-6080-7438d60d0000 pid=3542 execve guuid=c8355a1c-1700-0000-6080-7438d70d0000 pid=3543 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=c8355a1c-1700-0000-6080-7438d70d0000 pid=3543 execve guuid=c1d4b71c-1700-0000-6080-7438da0d0000 pid=3546 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=c1d4b71c-1700-0000-6080-7438da0d0000 pid=3546 execve guuid=e317151d-1700-0000-6080-7438dc0d0000 pid=3548 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=e317151d-1700-0000-6080-7438dc0d0000 pid=3548 execve guuid=91456a1d-1700-0000-6080-7438df0d0000 pid=3551 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=91456a1d-1700-0000-6080-7438df0d0000 pid=3551 execve guuid=3182c91d-1700-0000-6080-7438e10d0000 pid=3553 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=3182c91d-1700-0000-6080-7438e10d0000 pid=3553 execve guuid=81d8251e-1700-0000-6080-7438e40d0000 pid=3556 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=81d8251e-1700-0000-6080-7438e40d0000 pid=3556 execve guuid=db5d831e-1700-0000-6080-7438e60d0000 pid=3558 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=db5d831e-1700-0000-6080-7438e60d0000 pid=3558 execve guuid=cd7ae21e-1700-0000-6080-7438e80d0000 pid=3560 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=cd7ae21e-1700-0000-6080-7438e80d0000 pid=3560 execve guuid=28ea441f-1700-0000-6080-7438ea0d0000 pid=3562 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=28ea441f-1700-0000-6080-7438ea0d0000 pid=3562 execve guuid=3e01ab1f-1700-0000-6080-7438ed0d0000 pid=3565 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=3e01ab1f-1700-0000-6080-7438ed0d0000 pid=3565 execve guuid=dd5fff1f-1700-0000-6080-7438ef0d0000 pid=3567 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=dd5fff1f-1700-0000-6080-7438ef0d0000 pid=3567 execve guuid=13345e20-1700-0000-6080-7438f20d0000 pid=3570 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=13345e20-1700-0000-6080-7438f20d0000 pid=3570 execve guuid=c578c120-1700-0000-6080-7438f30d0000 pid=3571 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=c578c120-1700-0000-6080-7438f30d0000 pid=3571 execve guuid=bc113f21-1700-0000-6080-7438f40d0000 pid=3572 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=bc113f21-1700-0000-6080-7438f40d0000 pid=3572 execve guuid=4323b321-1700-0000-6080-7438f60d0000 pid=3574 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=4323b321-1700-0000-6080-7438f60d0000 pid=3574 execve guuid=85161322-1700-0000-6080-7438f70d0000 pid=3575 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=85161322-1700-0000-6080-7438f70d0000 pid=3575 execve guuid=9f347322-1700-0000-6080-7438fa0d0000 pid=3578 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=9f347322-1700-0000-6080-7438fa0d0000 pid=3578 execve guuid=ef45d122-1700-0000-6080-7438fc0d0000 pid=3580 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=ef45d122-1700-0000-6080-7438fc0d0000 pid=3580 execve guuid=6c9c2c23-1700-0000-6080-7438fe0d0000 pid=3582 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=6c9c2c23-1700-0000-6080-7438fe0d0000 pid=3582 execve guuid=5e7e7f23-1700-0000-6080-7438000e0000 pid=3584 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=5e7e7f23-1700-0000-6080-7438000e0000 pid=3584 execve guuid=afb7de23-1700-0000-6080-7438030e0000 pid=3587 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=afb7de23-1700-0000-6080-7438030e0000 pid=3587 execve guuid=529d3824-1700-0000-6080-7438050e0000 pid=3589 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=529d3824-1700-0000-6080-7438050e0000 pid=3589 execve guuid=d3b89224-1700-0000-6080-7438080e0000 pid=3592 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=d3b89224-1700-0000-6080-7438080e0000 pid=3592 execve guuid=0885eb24-1700-0000-6080-74380a0e0000 pid=3594 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=0885eb24-1700-0000-6080-74380a0e0000 pid=3594 execve guuid=8a794825-1700-0000-6080-74380c0e0000 pid=3596 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=8a794825-1700-0000-6080-74380c0e0000 pid=3596 execve guuid=850ca625-1700-0000-6080-74380f0e0000 pid=3599 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=850ca625-1700-0000-6080-74380f0e0000 pid=3599 execve guuid=c1510426-1700-0000-6080-7438110e0000 pid=3601 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=c1510426-1700-0000-6080-7438110e0000 pid=3601 execve guuid=47e76126-1700-0000-6080-7438140e0000 pid=3604 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=47e76126-1700-0000-6080-7438140e0000 pid=3604 execve guuid=e63abc26-1700-0000-6080-7438160e0000 pid=3606 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=e63abc26-1700-0000-6080-7438160e0000 pid=3606 execve guuid=98851527-1700-0000-6080-7438190e0000 pid=3609 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=98851527-1700-0000-6080-7438190e0000 pid=3609 execve guuid=566a7527-1700-0000-6080-74381b0e0000 pid=3611 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=566a7527-1700-0000-6080-74381b0e0000 pid=3611 execve guuid=d8b5d527-1700-0000-6080-74381e0e0000 pid=3614 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=d8b5d527-1700-0000-6080-74381e0e0000 pid=3614 execve guuid=8fdb3628-1700-0000-6080-7438200e0000 pid=3616 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=8fdb3628-1700-0000-6080-7438200e0000 pid=3616 execve guuid=7c099528-1700-0000-6080-7438220e0000 pid=3618 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7c099528-1700-0000-6080-7438220e0000 pid=3618 execve guuid=3ebbf928-1700-0000-6080-7438250e0000 pid=3621 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=3ebbf928-1700-0000-6080-7438250e0000 pid=3621 execve guuid=dcb96229-1700-0000-6080-7438270e0000 pid=3623 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=dcb96229-1700-0000-6080-7438270e0000 pid=3623 execve guuid=500bbe29-1700-0000-6080-74382c0e0000 pid=3628 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=500bbe29-1700-0000-6080-74382c0e0000 pid=3628 execve guuid=86b2152a-1700-0000-6080-74382e0e0000 pid=3630 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=86b2152a-1700-0000-6080-74382e0e0000 pid=3630 execve guuid=26f9712a-1700-0000-6080-7438300e0000 pid=3632 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=26f9712a-1700-0000-6080-7438300e0000 pid=3632 execve guuid=28edd02a-1700-0000-6080-7438320e0000 pid=3634 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=28edd02a-1700-0000-6080-7438320e0000 pid=3634 execve guuid=398d2e2b-1700-0000-6080-7438340e0000 pid=3636 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=398d2e2b-1700-0000-6080-7438340e0000 pid=3636 execve guuid=29b5882b-1700-0000-6080-7438360e0000 pid=3638 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=29b5882b-1700-0000-6080-7438360e0000 pid=3638 execve guuid=1417e32b-1700-0000-6080-7438390e0000 pid=3641 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=1417e32b-1700-0000-6080-7438390e0000 pid=3641 execve guuid=4f1c412c-1700-0000-6080-74383b0e0000 pid=3643 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=4f1c412c-1700-0000-6080-74383b0e0000 pid=3643 execve guuid=2aad9c2c-1700-0000-6080-74383d0e0000 pid=3645 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=2aad9c2c-1700-0000-6080-74383d0e0000 pid=3645 execve guuid=7654f82c-1700-0000-6080-74383f0e0000 pid=3647 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7654f82c-1700-0000-6080-74383f0e0000 pid=3647 execve guuid=83d35c2d-1700-0000-6080-7438410e0000 pid=3649 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=83d35c2d-1700-0000-6080-7438410e0000 pid=3649 execve guuid=92b3b82d-1700-0000-6080-7438440e0000 pid=3652 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=92b3b82d-1700-0000-6080-7438440e0000 pid=3652 execve guuid=f5271b2e-1700-0000-6080-7438450e0000 pid=3653 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=f5271b2e-1700-0000-6080-7438450e0000 pid=3653 execve guuid=eb58862e-1700-0000-6080-7438480e0000 pid=3656 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=eb58862e-1700-0000-6080-7438480e0000 pid=3656 execve guuid=5d3bef2e-1700-0000-6080-74384a0e0000 pid=3658 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=5d3bef2e-1700-0000-6080-74384a0e0000 pid=3658 execve guuid=a3fd572f-1700-0000-6080-74384d0e0000 pid=3661 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=a3fd572f-1700-0000-6080-74384d0e0000 pid=3661 execve guuid=1465ba2f-1700-0000-6080-74384f0e0000 pid=3663 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=1465ba2f-1700-0000-6080-74384f0e0000 pid=3663 execve guuid=58711a30-1700-0000-6080-7438510e0000 pid=3665 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=58711a30-1700-0000-6080-7438510e0000 pid=3665 execve guuid=864c7b30-1700-0000-6080-7438530e0000 pid=3667 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=864c7b30-1700-0000-6080-7438530e0000 pid=3667 execve guuid=86c2da30-1700-0000-6080-7438560e0000 pid=3670 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=86c2da30-1700-0000-6080-7438560e0000 pid=3670 execve guuid=56c13c31-1700-0000-6080-7438580e0000 pid=3672 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=56c13c31-1700-0000-6080-7438580e0000 pid=3672 execve guuid=2f42a731-1700-0000-6080-74385b0e0000 pid=3675 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=2f42a731-1700-0000-6080-74385b0e0000 pid=3675 execve guuid=e9df0f32-1700-0000-6080-74385d0e0000 pid=3677 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=e9df0f32-1700-0000-6080-74385d0e0000 pid=3677 execve guuid=90dc7232-1700-0000-6080-74385f0e0000 pid=3679 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=90dc7232-1700-0000-6080-74385f0e0000 pid=3679 execve guuid=de66d532-1700-0000-6080-7438620e0000 pid=3682 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=de66d532-1700-0000-6080-7438620e0000 pid=3682 execve guuid=21c32e33-1700-0000-6080-7438640e0000 pid=3684 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=21c32e33-1700-0000-6080-7438640e0000 pid=3684 execve guuid=7cfc8c33-1700-0000-6080-7438660e0000 pid=3686 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7cfc8c33-1700-0000-6080-7438660e0000 pid=3686 execve guuid=b245e133-1700-0000-6080-7438680e0000 pid=3688 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=b245e133-1700-0000-6080-7438680e0000 pid=3688 execve guuid=54623b34-1700-0000-6080-74386a0e0000 pid=3690 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=54623b34-1700-0000-6080-74386a0e0000 pid=3690 execve guuid=5d629034-1700-0000-6080-74386c0e0000 pid=3692 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=5d629034-1700-0000-6080-74386c0e0000 pid=3692 execve guuid=36c5e834-1700-0000-6080-74386f0e0000 pid=3695 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=36c5e834-1700-0000-6080-74386f0e0000 pid=3695 execve guuid=b8f54235-1700-0000-6080-7438700e0000 pid=3696 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=b8f54235-1700-0000-6080-7438700e0000 pid=3696 execve guuid=804bac35-1700-0000-6080-7438730e0000 pid=3699 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=804bac35-1700-0000-6080-7438730e0000 pid=3699 execve guuid=2f120e36-1700-0000-6080-7438750e0000 pid=3701 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=2f120e36-1700-0000-6080-7438750e0000 pid=3701 execve guuid=6ba26c36-1700-0000-6080-7438770e0000 pid=3703 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=6ba26c36-1700-0000-6080-7438770e0000 pid=3703 execve guuid=713dce36-1700-0000-6080-7438780e0000 pid=3704 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=713dce36-1700-0000-6080-7438780e0000 pid=3704 execve guuid=20be3f37-1700-0000-6080-74387a0e0000 pid=3706 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=20be3f37-1700-0000-6080-74387a0e0000 pid=3706 execve guuid=dfd5a137-1700-0000-6080-74387c0e0000 pid=3708 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=dfd5a137-1700-0000-6080-74387c0e0000 pid=3708 execve guuid=230d0738-1700-0000-6080-74387f0e0000 pid=3711 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=230d0738-1700-0000-6080-74387f0e0000 pid=3711 execve guuid=385b6738-1700-0000-6080-7438810e0000 pid=3713 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=385b6738-1700-0000-6080-7438810e0000 pid=3713 execve guuid=1dd9cb38-1700-0000-6080-7438840e0000 pid=3716 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=1dd9cb38-1700-0000-6080-7438840e0000 pid=3716 execve guuid=90aa2f39-1700-0000-6080-7438860e0000 pid=3718 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=90aa2f39-1700-0000-6080-7438860e0000 pid=3718 execve guuid=cb7a9939-1700-0000-6080-7438890e0000 pid=3721 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=cb7a9939-1700-0000-6080-7438890e0000 pid=3721 execve guuid=7a59f839-1700-0000-6080-74388b0e0000 pid=3723 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=7a59f839-1700-0000-6080-74388b0e0000 pid=3723 execve guuid=737f553a-1700-0000-6080-74388f0e0000 pid=3727 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=737f553a-1700-0000-6080-74388f0e0000 pid=3727 execve guuid=17b2b23a-1700-0000-6080-7438900e0000 pid=3728 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=17b2b23a-1700-0000-6080-7438900e0000 pid=3728 execve guuid=e327103b-1700-0000-6080-7438940e0000 pid=3732 /usr/bin/ls guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=e327103b-1700-0000-6080-7438940e0000 pid=3732 execve guuid=4a8c653b-1700-0000-6080-7438980e0000 pid=3736 /usr/bin/rm guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=4a8c653b-1700-0000-6080-7438980e0000 pid=3736 execve guuid=b3579f3b-1700-0000-6080-7438990e0000 pid=3737 /usr/bin/wget net send-data write-file guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=b3579f3b-1700-0000-6080-7438990e0000 pid=3737 execve guuid=ebd08680-1700-0000-6080-74388b0f0000 pid=3979 /usr/bin/chmod guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=ebd08680-1700-0000-6080-74388b0f0000 pid=3979 execve guuid=692c1681-1700-0000-6080-74388c0f0000 pid=3980 /tmp/azAJ guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=692c1681-1700-0000-6080-74388c0f0000 pid=3980 execve guuid=f9cb3c82-1700-0000-6080-74388f0f0000 pid=3983 /usr/bin/rm guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=f9cb3c82-1700-0000-6080-74388f0f0000 pid=3983 execve guuid=bbff9982-1700-0000-6080-7438900f0000 pid=3984 /usr/bin/wget net send-data write-file guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=bbff9982-1700-0000-6080-7438900f0000 pid=3984 execve guuid=4e18c8c8-1700-0000-6080-743833100000 pid=4147 /usr/bin/chmod guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=4e18c8c8-1700-0000-6080-743833100000 pid=4147 execve guuid=97af35c9-1700-0000-6080-743835100000 pid=4149 /tmp/kAqy guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=97af35c9-1700-0000-6080-743835100000 pid=4149 execve guuid=c0ef6bcb-1700-0000-6080-74383f100000 pid=4159 /usr/bin/rm guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=c0ef6bcb-1700-0000-6080-74383f100000 pid=4159 execve guuid=6c9ec2cb-1700-0000-6080-743841100000 pid=4161 /usr/bin/wget net send-data write-file guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=6c9ec2cb-1700-0000-6080-743841100000 pid=4161 execve guuid=1601bbd2-1700-0000-6080-743851100000 pid=4177 /usr/bin/chmod guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=1601bbd2-1700-0000-6080-743851100000 pid=4177 execve guuid=40fd17d3-1700-0000-6080-743855100000 pid=4181 /tmp/XmgG guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=40fd17d3-1700-0000-6080-743855100000 pid=4181 execve guuid=1add5fd4-1700-0000-6080-743857100000 pid=4183 /usr/bin/rm guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=1add5fd4-1700-0000-6080-743857100000 pid=4183 execve guuid=bc2fc6d4-1700-0000-6080-74385b100000 pid=4187 /usr/bin/wget net send-data write-file guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=bc2fc6d4-1700-0000-6080-74385b100000 pid=4187 execve guuid=5e0115eb-1700-0000-6080-743891100000 pid=4241 /usr/bin/chmod guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=5e0115eb-1700-0000-6080-743891100000 pid=4241 execve guuid=a87b5aeb-1700-0000-6080-743895100000 pid=4245 /tmp/19io guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=a87b5aeb-1700-0000-6080-743895100000 pid=4245 execve guuid=6e7ad6ec-1700-0000-6080-74389c100000 pid=4252 /usr/bin/rm guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=6e7ad6ec-1700-0000-6080-74389c100000 pid=4252 execve guuid=52731bed-1700-0000-6080-7438a0100000 pid=4256 /usr/bin/wget net send-data write-file guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=52731bed-1700-0000-6080-7438a0100000 pid=4256 execve guuid=593c19f4-1700-0000-6080-7438bc100000 pid=4284 /usr/bin/chmod guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=593c19f4-1700-0000-6080-7438bc100000 pid=4284 execve guuid=06065df4-1700-0000-6080-7438be100000 pid=4286 /tmp/f9f5 guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=06065df4-1700-0000-6080-7438be100000 pid=4286 execve guuid=d3cd5af5-1700-0000-6080-7438c3100000 pid=4291 /usr/bin/rm delete-file guuid=bd3bc80a-1700-0000-6080-7438930d0000 pid=3475->guuid=d3cd5af5-1700-0000-6080-7438c3100000 pid=4291 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=b3579f3b-1700-0000-6080-7438990e0000 pid=3737->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=bbff9982-1700-0000-6080-7438900f0000 pid=3984->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=6c9ec2cb-1700-0000-6080-743841100000 pid=4161->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=bc2fc6d4-1700-0000-6080-74385b100000 pid=4187->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=52731bed-1700-0000-6080-7438a0100000 pid=4256->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-05 04:52:30 UTC
File Type:
Text (Shell)
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d58fea3df011e3434ac8d727d933e9220cabaf805ea5de89f475f9f1e84dbfd5

(this sample)

  
Delivery method
Distributed via web download

Comments