MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d5d7d159eb313151dfca81568218f93e7d27ee65d7b26d3a2489cdc1fa7689fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: d5d7d159eb313151dfca81568218f93e7d27ee65d7b26d3a2489cdc1fa7689fa
SHA3-384 hash: f3ab068334c873492e36cfe531e146bb38c97b4313ec5dc25c013533ec7d5005a841651990357917fe9ed78cd87cf508
SHA1 hash: 03dde69cb0feec68cddf1ec2805791a6f5cb0a0e
MD5 hash: 0be5b34504257e8bd11c25afc998439f
humanhash: december-november-twenty-hot
File name:1.sh
Download: download sample
File size:6'389 bytes
First seen:2025-08-26 07:37:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:GF3mBbGOBqy3p83NqC12uEk7s4AgnAc9POZj9POZjoofI0rNwDZeGpi60Ur8o/xs:GF3mBbGOBqy3p83NqC12uEk7s4AgnAcZ
TLSH T1D9D14DF6B48652BCDD9FCD3A511069BD118AA99B2A8B0D6887FE24753C89FCC1C04DD3
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mipsn/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arcn/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i468n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i686n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86_64n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mpsln/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.armn/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm5n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm6n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm7n/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.ppcn/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.spcn/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.m68kn/an/aelf ua-wget
http://196.251.87.166/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=d1059cd2-1600-0000-d086-cd10be0c0000 pid=3262 /usr/bin/sudo guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271 /tmp/sample.bin guuid=d1059cd2-1600-0000-d086-cd10be0c0000 pid=3262->guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271 execve guuid=7ab92ad5-1600-0000-d086-cd10c90c0000 pid=3273 /usr/bin/cp guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=7ab92ad5-1600-0000-d086-cd10c90c0000 pid=3273 execve guuid=b3f8fdd5-1600-0000-d086-cd10ce0c0000 pid=3278 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=b3f8fdd5-1600-0000-d086-cd10ce0c0000 pid=3278 execve guuid=6f9d25da-1600-0000-d086-cd10d80c0000 pid=3288 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=6f9d25da-1600-0000-d086-cd10d80c0000 pid=3288 execve guuid=b8ff4fe0-1600-0000-d086-cd10e70c0000 pid=3303 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=b8ff4fe0-1600-0000-d086-cd10e70c0000 pid=3303 execve guuid=cff7a4e0-1600-0000-d086-cd10ea0c0000 pid=3306 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=cff7a4e0-1600-0000-d086-cd10ea0c0000 pid=3306 clone guuid=b5cfdae0-1600-0000-d086-cd10eb0c0000 pid=3307 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=b5cfdae0-1600-0000-d086-cd10eb0c0000 pid=3307 execve guuid=21f42ce1-1600-0000-d086-cd10ed0c0000 pid=3309 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=21f42ce1-1600-0000-d086-cd10ed0c0000 pid=3309 execve guuid=93301ce4-1600-0000-d086-cd10f70c0000 pid=3319 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=93301ce4-1600-0000-d086-cd10f70c0000 pid=3319 execve guuid=51ed44e9-1600-0000-d086-cd10fb0c0000 pid=3323 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=51ed44e9-1600-0000-d086-cd10fb0c0000 pid=3323 execve guuid=d2fa98e9-1600-0000-d086-cd10fc0c0000 pid=3324 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=d2fa98e9-1600-0000-d086-cd10fc0c0000 pid=3324 clone guuid=6a46c1e9-1600-0000-d086-cd10fd0c0000 pid=3325 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=6a46c1e9-1600-0000-d086-cd10fd0c0000 pid=3325 execve guuid=f74e1eea-1600-0000-d086-cd10fe0c0000 pid=3326 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=f74e1eea-1600-0000-d086-cd10fe0c0000 pid=3326 execve guuid=658186ec-1600-0000-d086-cd10000d0000 pid=3328 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=658186ec-1600-0000-d086-cd10000d0000 pid=3328 execve guuid=9f5015f1-1600-0000-d086-cd100c0d0000 pid=3340 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=9f5015f1-1600-0000-d086-cd100c0d0000 pid=3340 execve guuid=10065ef1-1600-0000-d086-cd100d0d0000 pid=3341 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=10065ef1-1600-0000-d086-cd100d0d0000 pid=3341 clone guuid=4eb285f1-1600-0000-d086-cd100e0d0000 pid=3342 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=4eb285f1-1600-0000-d086-cd100e0d0000 pid=3342 execve guuid=5588d5f1-1600-0000-d086-cd10100d0000 pid=3344 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=5588d5f1-1600-0000-d086-cd10100d0000 pid=3344 execve guuid=e57706f4-1600-0000-d086-cd10170d0000 pid=3351 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=e57706f4-1600-0000-d086-cd10170d0000 pid=3351 execve guuid=b395c3f7-1600-0000-d086-cd10200d0000 pid=3360 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=b395c3f7-1600-0000-d086-cd10200d0000 pid=3360 execve guuid=aa6201f8-1600-0000-d086-cd10220d0000 pid=3362 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=aa6201f8-1600-0000-d086-cd10220d0000 pid=3362 clone guuid=7f9d2ff8-1600-0000-d086-cd10240d0000 pid=3364 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=7f9d2ff8-1600-0000-d086-cd10240d0000 pid=3364 execve guuid=04446ff8-1600-0000-d086-cd10260d0000 pid=3366 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=04446ff8-1600-0000-d086-cd10260d0000 pid=3366 execve guuid=1fbd8ffa-1600-0000-d086-cd102e0d0000 pid=3374 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=1fbd8ffa-1600-0000-d086-cd102e0d0000 pid=3374 execve guuid=8c8908fe-1600-0000-d086-cd10380d0000 pid=3384 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=8c8908fe-1600-0000-d086-cd10380d0000 pid=3384 execve guuid=dddc65fe-1600-0000-d086-cd10390d0000 pid=3385 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=dddc65fe-1600-0000-d086-cd10390d0000 pid=3385 clone guuid=528baefe-1600-0000-d086-cd103b0d0000 pid=3387 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=528baefe-1600-0000-d086-cd103b0d0000 pid=3387 execve guuid=066206ff-1600-0000-d086-cd103d0d0000 pid=3389 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=066206ff-1600-0000-d086-cd103d0d0000 pid=3389 execve guuid=72039901-1700-0000-d086-cd10450d0000 pid=3397 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=72039901-1700-0000-d086-cd10450d0000 pid=3397 execve guuid=31549705-1700-0000-d086-cd10500d0000 pid=3408 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=31549705-1700-0000-d086-cd10500d0000 pid=3408 execve guuid=536fe805-1700-0000-d086-cd10510d0000 pid=3409 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=536fe805-1700-0000-d086-cd10510d0000 pid=3409 clone guuid=a5213706-1700-0000-d086-cd10530d0000 pid=3411 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=a5213706-1700-0000-d086-cd10530d0000 pid=3411 execve guuid=d4d99406-1700-0000-d086-cd10550d0000 pid=3413 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=d4d99406-1700-0000-d086-cd10550d0000 pid=3413 execve guuid=3f871d09-1700-0000-d086-cd105d0d0000 pid=3421 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=3f871d09-1700-0000-d086-cd105d0d0000 pid=3421 execve guuid=9a7c490d-1700-0000-d086-cd106a0d0000 pid=3434 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=9a7c490d-1700-0000-d086-cd106a0d0000 pid=3434 execve guuid=798e960d-1700-0000-d086-cd106c0d0000 pid=3436 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=798e960d-1700-0000-d086-cd106c0d0000 pid=3436 clone guuid=497cca0d-1700-0000-d086-cd106d0d0000 pid=3437 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=497cca0d-1700-0000-d086-cd106d0d0000 pid=3437 execve guuid=7e4d240e-1700-0000-d086-cd106f0d0000 pid=3439 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=7e4d240e-1700-0000-d086-cd106f0d0000 pid=3439 execve guuid=8cd0da10-1700-0000-d086-cd10780d0000 pid=3448 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=8cd0da10-1700-0000-d086-cd10780d0000 pid=3448 execve guuid=e1c48514-1700-0000-d086-cd10840d0000 pid=3460 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=e1c48514-1700-0000-d086-cd10840d0000 pid=3460 execve guuid=e12bde14-1700-0000-d086-cd10860d0000 pid=3462 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=e12bde14-1700-0000-d086-cd10860d0000 pid=3462 clone guuid=5b331615-1700-0000-d086-cd10870d0000 pid=3463 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=5b331615-1700-0000-d086-cd10870d0000 pid=3463 execve guuid=198d6b15-1700-0000-d086-cd10890d0000 pid=3465 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=198d6b15-1700-0000-d086-cd10890d0000 pid=3465 execve guuid=c4a5e217-1700-0000-d086-cd10920d0000 pid=3474 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=c4a5e217-1700-0000-d086-cd10920d0000 pid=3474 execve guuid=10f40c1b-1700-0000-d086-cd109e0d0000 pid=3486 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=10f40c1b-1700-0000-d086-cd109e0d0000 pid=3486 execve guuid=6a124b1b-1700-0000-d086-cd10a00d0000 pid=3488 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=6a124b1b-1700-0000-d086-cd10a00d0000 pid=3488 clone guuid=f0306b1b-1700-0000-d086-cd10a10d0000 pid=3489 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=f0306b1b-1700-0000-d086-cd10a10d0000 pid=3489 execve guuid=71b7ae1b-1700-0000-d086-cd10a30d0000 pid=3491 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=71b7ae1b-1700-0000-d086-cd10a30d0000 pid=3491 execve guuid=c9e7c61d-1700-0000-d086-cd10ab0d0000 pid=3499 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=c9e7c61d-1700-0000-d086-cd10ab0d0000 pid=3499 execve guuid=2e740221-1700-0000-d086-cd10b60d0000 pid=3510 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=2e740221-1700-0000-d086-cd10b60d0000 pid=3510 execve guuid=07075421-1700-0000-d086-cd10b80d0000 pid=3512 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=07075421-1700-0000-d086-cd10b80d0000 pid=3512 clone guuid=7bf57a21-1700-0000-d086-cd10b90d0000 pid=3513 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=7bf57a21-1700-0000-d086-cd10b90d0000 pid=3513 execve guuid=6b2ed121-1700-0000-d086-cd10bb0d0000 pid=3515 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=6b2ed121-1700-0000-d086-cd10bb0d0000 pid=3515 execve guuid=37876024-1700-0000-d086-cd10c40d0000 pid=3524 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=37876024-1700-0000-d086-cd10c40d0000 pid=3524 execve guuid=83e30628-1700-0000-d086-cd10cb0d0000 pid=3531 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=83e30628-1700-0000-d086-cd10cb0d0000 pid=3531 execve guuid=e0524928-1700-0000-d086-cd10cc0d0000 pid=3532 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=e0524928-1700-0000-d086-cd10cc0d0000 pid=3532 clone guuid=5fa16828-1700-0000-d086-cd10cd0d0000 pid=3533 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=5fa16828-1700-0000-d086-cd10cd0d0000 pid=3533 execve guuid=af98a928-1700-0000-d086-cd10ce0d0000 pid=3534 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=af98a928-1700-0000-d086-cd10ce0d0000 pid=3534 execve guuid=8833eb2a-1700-0000-d086-cd10d20d0000 pid=3538 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=8833eb2a-1700-0000-d086-cd10d20d0000 pid=3538 execve guuid=34a72e2e-1700-0000-d086-cd10db0d0000 pid=3547 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=34a72e2e-1700-0000-d086-cd10db0d0000 pid=3547 execve guuid=f163862e-1700-0000-d086-cd10dd0d0000 pid=3549 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=f163862e-1700-0000-d086-cd10dd0d0000 pid=3549 clone guuid=d4efaf2e-1700-0000-d086-cd10df0d0000 pid=3551 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=d4efaf2e-1700-0000-d086-cd10df0d0000 pid=3551 execve guuid=8319002f-1700-0000-d086-cd10e00d0000 pid=3552 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=8319002f-1700-0000-d086-cd10e00d0000 pid=3552 execve guuid=81234a31-1700-0000-d086-cd10e50d0000 pid=3557 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=81234a31-1700-0000-d086-cd10e50d0000 pid=3557 execve guuid=5134a734-1700-0000-d086-cd10ed0d0000 pid=3565 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=5134a734-1700-0000-d086-cd10ed0d0000 pid=3565 execve guuid=29e2f234-1700-0000-d086-cd10ef0d0000 pid=3567 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=29e2f234-1700-0000-d086-cd10ef0d0000 pid=3567 clone guuid=f9e21635-1700-0000-d086-cd10f00d0000 pid=3568 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=f9e21635-1700-0000-d086-cd10f00d0000 pid=3568 execve guuid=154b6335-1700-0000-d086-cd10f20d0000 pid=3570 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=154b6335-1700-0000-d086-cd10f20d0000 pid=3570 execve guuid=97c3a137-1700-0000-d086-cd10fa0d0000 pid=3578 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=97c3a137-1700-0000-d086-cd10fa0d0000 pid=3578 execve guuid=eb00283b-1700-0000-d086-cd10020e0000 pid=3586 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=eb00283b-1700-0000-d086-cd10020e0000 pid=3586 execve guuid=d06b7a3b-1700-0000-d086-cd10040e0000 pid=3588 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=d06b7a3b-1700-0000-d086-cd10040e0000 pid=3588 clone guuid=05b29d3b-1700-0000-d086-cd10060e0000 pid=3590 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=05b29d3b-1700-0000-d086-cd10060e0000 pid=3590 execve guuid=2f7bfa3b-1700-0000-d086-cd10080e0000 pid=3592 /usr/bin/wget net send-data guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=2f7bfa3b-1700-0000-d086-cd10080e0000 pid=3592 execve guuid=b7a04d3e-1700-0000-d086-cd100f0e0000 pid=3599 /usr/bin/curl net send-data write-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=b7a04d3e-1700-0000-d086-cd100f0e0000 pid=3599 execve guuid=10816241-1700-0000-d086-cd10160e0000 pid=3606 /usr/bin/chmod guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=10816241-1700-0000-d086-cd10160e0000 pid=3606 execve guuid=bc81ae41-1700-0000-d086-cd10180e0000 pid=3608 /usr/bin/bash guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=bc81ae41-1700-0000-d086-cd10180e0000 pid=3608 clone guuid=51a2d541-1700-0000-d086-cd101a0e0000 pid=3610 /usr/bin/rm delete-file guuid=de62d3d4-1600-0000-d086-cd10c70c0000 pid=3271->guuid=51a2d541-1700-0000-d086-cd101a0e0000 pid=3610 execve e0e21a48-ffad-5b01-84ef-2ee6b5294738 196.251.87.166:80 guuid=b3f8fdd5-1600-0000-d086-cd10ce0c0000 pid=3278->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 214B guuid=6f9d25da-1600-0000-d086-cd10d80c0000 pid=3288->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 163B guuid=21f42ce1-1600-0000-d086-cd10ed0c0000 pid=3309->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=93301ce4-1600-0000-d086-cd10f70c0000 pid=3319->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=f74e1eea-1600-0000-d086-cd10fe0c0000 pid=3326->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 214B guuid=658186ec-1600-0000-d086-cd10000d0000 pid=3328->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 163B guuid=5588d5f1-1600-0000-d086-cd10100d0000 pid=3344->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=e57706f4-1600-0000-d086-cd10170d0000 pid=3351->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=04446ff8-1600-0000-d086-cd10260d0000 pid=3366->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=1fbd8ffa-1600-0000-d086-cd102e0d0000 pid=3374->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=066206ff-1600-0000-d086-cd103d0d0000 pid=3389->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 217B guuid=72039901-1700-0000-d086-cd10450d0000 pid=3397->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 166B guuid=d4d99406-1700-0000-d086-cd10550d0000 pid=3413->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=3f871d09-1700-0000-d086-cd105d0d0000 pid=3421->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=7e4d240e-1700-0000-d086-cd106f0d0000 pid=3439->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 214B guuid=8cd0da10-1700-0000-d086-cd10780d0000 pid=3448->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 163B guuid=198d6b15-1700-0000-d086-cd10890d0000 pid=3465->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=c4a5e217-1700-0000-d086-cd10920d0000 pid=3474->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=71b7ae1b-1700-0000-d086-cd10a30d0000 pid=3491->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=c9e7c61d-1700-0000-d086-cd10ab0d0000 pid=3499->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=6b2ed121-1700-0000-d086-cd10bb0d0000 pid=3515->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=37876024-1700-0000-d086-cd10c40d0000 pid=3524->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=af98a928-1700-0000-d086-cd10ce0d0000 pid=3534->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 214B guuid=8833eb2a-1700-0000-d086-cd10d20d0000 pid=3538->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 163B guuid=8319002f-1700-0000-d086-cd10e00d0000 pid=3552->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 214B guuid=81234a31-1700-0000-d086-cd10e50d0000 pid=3557->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 163B guuid=154b6335-1700-0000-d086-cd10f20d0000 pid=3570->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 215B guuid=97c3a137-1700-0000-d086-cd10fa0d0000 pid=3578->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 164B guuid=2f7bfa3b-1700-0000-d086-cd10080e0000 pid=3592->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 214B guuid=b7a04d3e-1700-0000-d086-cd100f0e0000 pid=3599->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 163B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-08-26 07:38:34 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d5d7d159eb313151dfca81568218f93e7d27ee65d7b26d3a2489cdc1fa7689fa

(this sample)

  
Delivery method
Distributed via web download

Comments