MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 de368f11cce30b2d70b4fe03a43f82d06a2890b12946e0ebbba645a0d4bb6d39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: de368f11cce30b2d70b4fe03a43f82d06a2890b12946e0ebbba645a0d4bb6d39
SHA3-384 hash: 1e3e71428b6107ae331125313873cb74b475d7df3369ae28ad4c64f61275db877e4c160a2592e79f009dd70368dd0a89
SHA1 hash: e9792e01dd6beefb581e39fe1fc005fcc0cdff55
MD5 hash: 72b1ef5696bcbf89e0a0d94d3eb13cf9
humanhash: magazine-virginia-april-seventeen
File name:cat.sh
Download: download sample
File size:1'894 bytes
First seen:2025-07-27 20:21:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:GwfDIdt/yNaK36hODOulfC+a1E1FxLB8wtc439o777Zn1mDu0LBtCPwH5cQA5Ly3:xfsJAFFDtvaCHtc4IZn0xGs5Yq
TLSH T1424197EE30645E5285C58E25B37181C9D0C5B9BF3ABECBE1E8577C2E485BD44301AA39
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://23.95.247.31/x86_64n/an/acensys elf ua-wget
http://23.95.247.31/aarch64n/an/acensys elf ua-wget
http://23.95.247.31/m68kn/an/acensys elf geofenced ua-wget USA
http://23.95.247.31/mipsn/an/acensys elf ua-wget
http://23.95.247.31/mipseln/an/acensys elf ua-wget
http://23.95.247.31/powerpcn/an/acensys elf ua-wget
http://23.95.247.31/sparcn/an/acensys elf ua-wget
http://23.95.247.31/sh4n/an/acensys elf ua-wget
http://23.95.247.31/arcn/an/acensys elf ua-wget
http://23.95.247.31/cskyn/an/acensys elf ua-wget
http://23.95.247.31/i486n/an/acensys elf ua-wget
http://23.95.247.31/armv4ln/an/acensys elf ua-wget
http://23.95.247.31/armv5ln/an/acensys elf ua-wget
http://23.95.247.31/armv6ln/an/acensys elf ua-wget
http://23.95.247.31/armv7ln/an/acensys elf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=46f9e22e-1a00-0000-5fe0-6a9e9f040000 pid=1183 /usr/bin/sudo guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190 /tmp/sample.bin guuid=46f9e22e-1a00-0000-5fe0-6a9e9f040000 pid=1183->guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190 execve guuid=050b6232-1a00-0000-5fe0-6a9ea9040000 pid=1193 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=050b6232-1a00-0000-5fe0-6a9ea9040000 pid=1193 execve guuid=726ff447-1a00-0000-5fe0-6a9edb040000 pid=1243 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=726ff447-1a00-0000-5fe0-6a9edb040000 pid=1243 execve guuid=1004be60-1a00-0000-5fe0-6a9e11050000 pid=1297 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=1004be60-1a00-0000-5fe0-6a9e11050000 pid=1297 execve guuid=4ed02161-1a00-0000-5fe0-6a9e12050000 pid=1298 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=4ed02161-1a00-0000-5fe0-6a9e12050000 pid=1298 clone guuid=da386661-1a00-0000-5fe0-6a9e14050000 pid=1300 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=da386661-1a00-0000-5fe0-6a9e14050000 pid=1300 execve guuid=a7e1de61-1a00-0000-5fe0-6a9e16050000 pid=1302 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=a7e1de61-1a00-0000-5fe0-6a9e16050000 pid=1302 execve guuid=cfb16876-1a00-0000-5fe0-6a9e22050000 pid=1314 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=cfb16876-1a00-0000-5fe0-6a9e22050000 pid=1314 execve guuid=32763d8e-1a00-0000-5fe0-6a9e2b050000 pid=1323 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=32763d8e-1a00-0000-5fe0-6a9e2b050000 pid=1323 execve guuid=148ca48e-1a00-0000-5fe0-6a9e2c050000 pid=1324 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=148ca48e-1a00-0000-5fe0-6a9e2c050000 pid=1324 clone guuid=7bbfce8e-1a00-0000-5fe0-6a9e2d050000 pid=1325 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=7bbfce8e-1a00-0000-5fe0-6a9e2d050000 pid=1325 execve guuid=0f4b728f-1a00-0000-5fe0-6a9e2f050000 pid=1327 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=0f4b728f-1a00-0000-5fe0-6a9e2f050000 pid=1327 execve guuid=310155a4-1a00-0000-5fe0-6a9e48050000 pid=1352 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=310155a4-1a00-0000-5fe0-6a9e48050000 pid=1352 execve guuid=af5655bd-1a00-0000-5fe0-6a9e54050000 pid=1364 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=af5655bd-1a00-0000-5fe0-6a9e54050000 pid=1364 execve guuid=55d4a6be-1a00-0000-5fe0-6a9e56050000 pid=1366 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=55d4a6be-1a00-0000-5fe0-6a9e56050000 pid=1366 clone guuid=f55a0dbf-1a00-0000-5fe0-6a9e58050000 pid=1368 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=f55a0dbf-1a00-0000-5fe0-6a9e58050000 pid=1368 execve guuid=f3b1a6bf-1a00-0000-5fe0-6a9e5b050000 pid=1371 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=f3b1a6bf-1a00-0000-5fe0-6a9e5b050000 pid=1371 execve guuid=057aa0d4-1a00-0000-5fe0-6a9e7f050000 pid=1407 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=057aa0d4-1a00-0000-5fe0-6a9e7f050000 pid=1407 execve guuid=226e18ea-1a00-0000-5fe0-6a9ead050000 pid=1453 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=226e18ea-1a00-0000-5fe0-6a9ead050000 pid=1453 execve guuid=72945bff-1a00-0000-5fe0-6a9eae050000 pid=1454 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=72945bff-1a00-0000-5fe0-6a9eae050000 pid=1454 clone guuid=a5b78eff-1a00-0000-5fe0-6a9eb0050000 pid=1456 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=a5b78eff-1a00-0000-5fe0-6a9eb0050000 pid=1456 execve guuid=660bfeff-1a00-0000-5fe0-6a9eb1050000 pid=1457 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=660bfeff-1a00-0000-5fe0-6a9eb1050000 pid=1457 execve guuid=59b1fa13-1b00-0000-5fe0-6a9ee8050000 pid=1512 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=59b1fa13-1b00-0000-5fe0-6a9ee8050000 pid=1512 execve guuid=b2ead22a-1b00-0000-5fe0-6a9e1f060000 pid=1567 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=b2ead22a-1b00-0000-5fe0-6a9e1f060000 pid=1567 execve guuid=9ad3402b-1b00-0000-5fe0-6a9e22060000 pid=1570 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=9ad3402b-1b00-0000-5fe0-6a9e22060000 pid=1570 clone guuid=425c782b-1b00-0000-5fe0-6a9e24060000 pid=1572 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=425c782b-1b00-0000-5fe0-6a9e24060000 pid=1572 execve guuid=bfedc12b-1b00-0000-5fe0-6a9e25060000 pid=1573 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=bfedc12b-1b00-0000-5fe0-6a9e25060000 pid=1573 execve guuid=123d4740-1b00-0000-5fe0-6a9e58060000 pid=1624 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=123d4740-1b00-0000-5fe0-6a9e58060000 pid=1624 execve guuid=4d245555-1b00-0000-5fe0-6a9ea5060000 pid=1701 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=4d245555-1b00-0000-5fe0-6a9ea5060000 pid=1701 execve guuid=2a93a455-1b00-0000-5fe0-6a9ea7060000 pid=1703 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=2a93a455-1b00-0000-5fe0-6a9ea7060000 pid=1703 clone guuid=23c7c755-1b00-0000-5fe0-6a9ea8060000 pid=1704 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=23c7c755-1b00-0000-5fe0-6a9ea8060000 pid=1704 execve guuid=59400a56-1b00-0000-5fe0-6a9eaa060000 pid=1706 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=59400a56-1b00-0000-5fe0-6a9eaa060000 pid=1706 execve guuid=00d94a6a-1b00-0000-5fe0-6a9eee060000 pid=1774 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=00d94a6a-1b00-0000-5fe0-6a9eee060000 pid=1774 execve guuid=7ffa1c7f-1b00-0000-5fe0-6a9e24070000 pid=1828 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=7ffa1c7f-1b00-0000-5fe0-6a9e24070000 pid=1828 execve guuid=e2a79e7f-1b00-0000-5fe0-6a9e26070000 pid=1830 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=e2a79e7f-1b00-0000-5fe0-6a9e26070000 pid=1830 clone guuid=af94d27f-1b00-0000-5fe0-6a9e28070000 pid=1832 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=af94d27f-1b00-0000-5fe0-6a9e28070000 pid=1832 execve guuid=52552f80-1b00-0000-5fe0-6a9e2a070000 pid=1834 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=52552f80-1b00-0000-5fe0-6a9e2a070000 pid=1834 execve guuid=68b0a194-1b00-0000-5fe0-6a9e4c070000 pid=1868 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=68b0a194-1b00-0000-5fe0-6a9e4c070000 pid=1868 execve guuid=6e803fab-1b00-0000-5fe0-6a9e77070000 pid=1911 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=6e803fab-1b00-0000-5fe0-6a9e77070000 pid=1911 execve guuid=07359aab-1b00-0000-5fe0-6a9e79070000 pid=1913 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=07359aab-1b00-0000-5fe0-6a9e79070000 pid=1913 clone guuid=d04fc9ab-1b00-0000-5fe0-6a9e7a070000 pid=1914 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=d04fc9ab-1b00-0000-5fe0-6a9e7a070000 pid=1914 execve guuid=8d9436ac-1b00-0000-5fe0-6a9e7d070000 pid=1917 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=8d9436ac-1b00-0000-5fe0-6a9e7d070000 pid=1917 execve guuid=ee333ac0-1b00-0000-5fe0-6a9eb3070000 pid=1971 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=ee333ac0-1b00-0000-5fe0-6a9eb3070000 pid=1971 execve guuid=967933d7-1b00-0000-5fe0-6a9edd070000 pid=2013 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=967933d7-1b00-0000-5fe0-6a9edd070000 pid=2013 execve guuid=90aa7dd7-1b00-0000-5fe0-6a9edf070000 pid=2015 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=90aa7dd7-1b00-0000-5fe0-6a9edf070000 pid=2015 clone guuid=4211a9d7-1b00-0000-5fe0-6a9ee1070000 pid=2017 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=4211a9d7-1b00-0000-5fe0-6a9ee1070000 pid=2017 execve guuid=8fb100d9-1b00-0000-5fe0-6a9ee6070000 pid=2022 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=8fb100d9-1b00-0000-5fe0-6a9ee6070000 pid=2022 execve guuid=9460e7ec-1b00-0000-5fe0-6a9e16080000 pid=2070 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=9460e7ec-1b00-0000-5fe0-6a9e16080000 pid=2070 execve guuid=b7eaa901-1c00-0000-5fe0-6a9e45080000 pid=2117 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=b7eaa901-1c00-0000-5fe0-6a9e45080000 pid=2117 execve guuid=22870902-1c00-0000-5fe0-6a9e46080000 pid=2118 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=22870902-1c00-0000-5fe0-6a9e46080000 pid=2118 clone guuid=8e452b02-1c00-0000-5fe0-6a9e48080000 pid=2120 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=8e452b02-1c00-0000-5fe0-6a9e48080000 pid=2120 execve guuid=0c0c9002-1c00-0000-5fe0-6a9e4a080000 pid=2122 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=0c0c9002-1c00-0000-5fe0-6a9e4a080000 pid=2122 execve guuid=474adb16-1c00-0000-5fe0-6a9e78080000 pid=2168 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=474adb16-1c00-0000-5fe0-6a9e78080000 pid=2168 execve guuid=e833c72c-1c00-0000-5fe0-6a9e96080000 pid=2198 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=e833c72c-1c00-0000-5fe0-6a9e96080000 pid=2198 execve guuid=4c77182d-1c00-0000-5fe0-6a9e98080000 pid=2200 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=4c77182d-1c00-0000-5fe0-6a9e98080000 pid=2200 clone guuid=8ce9532d-1c00-0000-5fe0-6a9e9a080000 pid=2202 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=8ce9532d-1c00-0000-5fe0-6a9e9a080000 pid=2202 execve guuid=6d12b52d-1c00-0000-5fe0-6a9e9c080000 pid=2204 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=6d12b52d-1c00-0000-5fe0-6a9e9c080000 pid=2204 execve guuid=9331da41-1c00-0000-5fe0-6a9edf080000 pid=2271 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=9331da41-1c00-0000-5fe0-6a9edf080000 pid=2271 execve guuid=32266f57-1c00-0000-5fe0-6a9e20090000 pid=2336 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=32266f57-1c00-0000-5fe0-6a9e20090000 pid=2336 execve guuid=083ebc57-1c00-0000-5fe0-6a9e22090000 pid=2338 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=083ebc57-1c00-0000-5fe0-6a9e22090000 pid=2338 clone guuid=dbe0db57-1c00-0000-5fe0-6a9e23090000 pid=2339 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=dbe0db57-1c00-0000-5fe0-6a9e23090000 pid=2339 execve guuid=720f4c58-1c00-0000-5fe0-6a9e24090000 pid=2340 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=720f4c58-1c00-0000-5fe0-6a9e24090000 pid=2340 execve guuid=1c308f6c-1c00-0000-5fe0-6a9e54090000 pid=2388 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=1c308f6c-1c00-0000-5fe0-6a9e54090000 pid=2388 execve guuid=eb99bc83-1c00-0000-5fe0-6a9e83090000 pid=2435 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=eb99bc83-1c00-0000-5fe0-6a9e83090000 pid=2435 execve guuid=bf2e0684-1c00-0000-5fe0-6a9e85090000 pid=2437 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=bf2e0684-1c00-0000-5fe0-6a9e85090000 pid=2437 clone guuid=8abe3784-1c00-0000-5fe0-6a9e86090000 pid=2438 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=8abe3784-1c00-0000-5fe0-6a9e86090000 pid=2438 execve guuid=306f8584-1c00-0000-5fe0-6a9e88090000 pid=2440 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=306f8584-1c00-0000-5fe0-6a9e88090000 pid=2440 execve guuid=17444698-1c00-0000-5fe0-6a9eb9090000 pid=2489 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=17444698-1c00-0000-5fe0-6a9eb9090000 pid=2489 execve guuid=e8f1adaf-1c00-0000-5fe0-6a9ee5090000 pid=2533 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=e8f1adaf-1c00-0000-5fe0-6a9ee5090000 pid=2533 execve guuid=095b13b0-1c00-0000-5fe0-6a9ee7090000 pid=2535 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=095b13b0-1c00-0000-5fe0-6a9ee7090000 pid=2535 clone guuid=689f46b0-1c00-0000-5fe0-6a9ee8090000 pid=2536 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=689f46b0-1c00-0000-5fe0-6a9ee8090000 pid=2536 execve guuid=13e0b6b0-1c00-0000-5fe0-6a9eea090000 pid=2538 /usr/bin/wget net send-data guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=13e0b6b0-1c00-0000-5fe0-6a9eea090000 pid=2538 execve guuid=010f31c5-1c00-0000-5fe0-6a9e150a0000 pid=2581 /usr/bin/curl net send-data write-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=010f31c5-1c00-0000-5fe0-6a9e150a0000 pid=2581 execve guuid=ba76cedb-1c00-0000-5fe0-6a9e4d0a0000 pid=2637 /usr/bin/chmod guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=ba76cedb-1c00-0000-5fe0-6a9e4d0a0000 pid=2637 execve guuid=0eff12dc-1c00-0000-5fe0-6a9e4f0a0000 pid=2639 /usr/bin/bash guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=0eff12dc-1c00-0000-5fe0-6a9e4f0a0000 pid=2639 clone guuid=1eeb34dc-1c00-0000-5fe0-6a9e500a0000 pid=2640 /usr/bin/rm delete-file guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=1eeb34dc-1c00-0000-5fe0-6a9e500a0000 pid=2640 execve guuid=2a338edc-1c00-0000-5fe0-6a9e520a0000 pid=2642 /usr/bin/bash zombie guuid=ee1aae31-1a00-0000-5fe0-6a9ea6040000 pid=1190->guuid=2a338edc-1c00-0000-5fe0-6a9e520a0000 pid=2642 clone 7b15a861-9a5c-5074-80df-e88f2f414d6d 23.95.247.31:80 guuid=050b6232-1a00-0000-5fe0-6a9ea9040000 pid=1193->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 133B guuid=726ff447-1a00-0000-5fe0-6a9edb040000 pid=1243->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 82B guuid=a7e1de61-1a00-0000-5fe0-6a9e16050000 pid=1302->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 134B guuid=cfb16876-1a00-0000-5fe0-6a9e22050000 pid=1314->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 83B guuid=0f4b728f-1a00-0000-5fe0-6a9e2f050000 pid=1327->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 131B guuid=310155a4-1a00-0000-5fe0-6a9e48050000 pid=1352->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 80B guuid=f3b1a6bf-1a00-0000-5fe0-6a9e5b050000 pid=1371->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 131B guuid=057aa0d4-1a00-0000-5fe0-6a9e7f050000 pid=1407->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 80B guuid=660bfeff-1a00-0000-5fe0-6a9eb1050000 pid=1457->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 133B guuid=59b1fa13-1b00-0000-5fe0-6a9ee8050000 pid=1512->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 82B guuid=bfedc12b-1b00-0000-5fe0-6a9e25060000 pid=1573->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 134B guuid=123d4740-1b00-0000-5fe0-6a9e58060000 pid=1624->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 83B guuid=59400a56-1b00-0000-5fe0-6a9eaa060000 pid=1706->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 132B guuid=00d94a6a-1b00-0000-5fe0-6a9eee060000 pid=1774->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 81B guuid=52552f80-1b00-0000-5fe0-6a9e2a070000 pid=1834->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 130B guuid=68b0a194-1b00-0000-5fe0-6a9e4c070000 pid=1868->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 79B guuid=8d9436ac-1b00-0000-5fe0-6a9e7d070000 pid=1917->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 130B guuid=ee333ac0-1b00-0000-5fe0-6a9eb3070000 pid=1971->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 79B guuid=8fb100d9-1b00-0000-5fe0-6a9ee6070000 pid=2022->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 131B guuid=9460e7ec-1b00-0000-5fe0-6a9e16080000 pid=2070->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 80B guuid=0c0c9002-1c00-0000-5fe0-6a9e4a080000 pid=2122->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 131B guuid=474adb16-1c00-0000-5fe0-6a9e78080000 pid=2168->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 80B guuid=6d12b52d-1c00-0000-5fe0-6a9e9c080000 pid=2204->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 133B guuid=9331da41-1c00-0000-5fe0-6a9edf080000 pid=2271->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 82B guuid=720f4c58-1c00-0000-5fe0-6a9e24090000 pid=2340->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 133B guuid=1c308f6c-1c00-0000-5fe0-6a9e54090000 pid=2388->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 82B guuid=306f8584-1c00-0000-5fe0-6a9e88090000 pid=2440->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 133B guuid=17444698-1c00-0000-5fe0-6a9eb9090000 pid=2489->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 82B guuid=13e0b6b0-1c00-0000-5fe0-6a9eea090000 pid=2538->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 133B guuid=010f31c5-1c00-0000-5fe0-6a9e150a0000 pid=2581->7b15a861-9a5c-5074-80df-e88f2f414d6d send: 82B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-07-27 20:15:50 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh de368f11cce30b2d70b4fe03a43f82d06a2890b12946e0ebbba645a0d4bb6d39

(this sample)

  
Delivery method
Distributed via web download

Comments