MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 decbeefb88f6deda17330f7690eb836ea7cbc915c4790ff6d9716f525e6e473f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: decbeefb88f6deda17330f7690eb836ea7cbc915c4790ff6d9716f525e6e473f
SHA3-384 hash: af26b833dc6117f223551dc00f5cd115578c307df8722ad776c7238e4144c9a75fa043dcf412f97bdc0637a3c818c2a4
SHA1 hash: b06e77b0d4352c7e443c2465c2f00d0634d6c934
MD5 hash: 594984aa3656ef8f6221c8c03d31e46c
humanhash: lion-snake-white-texas
File name:ok
Download: download sample
File size:1'620 bytes
First seen:2026-06-11 06:09:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:5VOrVD4Zjr9PrqrriXtdr720+8y87GprGWOxjIyX7rF1pNFXOrssRej6ryLp1XIX:iOzzX9dIUldFERedLdsZCEGOwWs5mRF
TLSH T1D93196AB1B1D3A8C0500CD9977752648E224D9DA214FE7A4FF0D08BDE2CC588B31BE5B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/471d97n/an/aelf ua-wget
http://45.205.1.59/70e6c0n/an/aelf ua-wget
http://45.205.1.59/53814en/an/aelf ua-wget
http://45.205.1.59/fd6142n/an/aelf ua-wget
http://45.205.1.59/7e4e10n/an/aelf ua-wget
http://45.205.1.59/60c20dn/an/aelf ua-wget
http://45.205.1.59/ed58c3n/an/aelf ua-wget
http://45.205.1.59/5f0b1fn/an/aelf ua-wget
http://45.205.1.59/c229bfn/an/aelf ua-wget
http://45.205.1.59/909fd4n/an/aelf ua-wget
http://45.205.1.59/58a8een/an/aelf ua-wget
http://45.205.1.59/0379adn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-11T03:21:00Z UTC
Last seen:
2026-06-12T18:38:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=499234e1-1600-0000-1be2-d200300d0000 pid=3376 /usr/bin/sudo guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380 /tmp/sample.bin guuid=499234e1-1600-0000-1be2-d200300d0000 pid=3376->guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380 execve guuid=fff149e4-1600-0000-1be2-d200360d0000 pid=3382 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=fff149e4-1600-0000-1be2-d200360d0000 pid=3382 execve guuid=6ffe4e00-1700-0000-1be2-d2007d0d0000 pid=3453 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=6ffe4e00-1700-0000-1be2-d2007d0d0000 pid=3453 execve guuid=f229a61f-1700-0000-1be2-d200af0d0000 pid=3503 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=f229a61f-1700-0000-1be2-d200af0d0000 pid=3503 execve guuid=52c00720-1700-0000-1be2-d200b10d0000 pid=3505 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=52c00720-1700-0000-1be2-d200b10d0000 pid=3505 clone guuid=31a08220-1700-0000-1be2-d200b40d0000 pid=3508 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=31a08220-1700-0000-1be2-d200b40d0000 pid=3508 execve guuid=4e05c320-1700-0000-1be2-d200b60d0000 pid=3510 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=4e05c320-1700-0000-1be2-d200b60d0000 pid=3510 execve guuid=ca9b2a21-1700-0000-1be2-d200b90d0000 pid=3513 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=ca9b2a21-1700-0000-1be2-d200b90d0000 pid=3513 execve guuid=3d503f3b-1700-0000-1be2-d200ee0d0000 pid=3566 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=3d503f3b-1700-0000-1be2-d200ee0d0000 pid=3566 execve guuid=4a6c7457-1700-0000-1be2-d2001d0e0000 pid=3613 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=4a6c7457-1700-0000-1be2-d2001d0e0000 pid=3613 execve guuid=7414fd57-1700-0000-1be2-d200200e0000 pid=3616 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=7414fd57-1700-0000-1be2-d200200e0000 pid=3616 clone guuid=9bce5b58-1700-0000-1be2-d200230e0000 pid=3619 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=9bce5b58-1700-0000-1be2-d200230e0000 pid=3619 execve guuid=2144e158-1700-0000-1be2-d200260e0000 pid=3622 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=2144e158-1700-0000-1be2-d200260e0000 pid=3622 execve guuid=9a326b59-1700-0000-1be2-d200280e0000 pid=3624 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=9a326b59-1700-0000-1be2-d200280e0000 pid=3624 execve guuid=23d88073-1700-0000-1be2-d2005c0e0000 pid=3676 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=23d88073-1700-0000-1be2-d2005c0e0000 pid=3676 execve guuid=a5bf1290-1700-0000-1be2-d200a50e0000 pid=3749 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=a5bf1290-1700-0000-1be2-d200a50e0000 pid=3749 execve guuid=df009390-1700-0000-1be2-d200a70e0000 pid=3751 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=df009390-1700-0000-1be2-d200a70e0000 pid=3751 clone guuid=d8feea90-1700-0000-1be2-d200a90e0000 pid=3753 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=d8feea90-1700-0000-1be2-d200a90e0000 pid=3753 execve guuid=606b7391-1700-0000-1be2-d200ac0e0000 pid=3756 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=606b7391-1700-0000-1be2-d200ac0e0000 pid=3756 execve guuid=08b0f791-1700-0000-1be2-d200ae0e0000 pid=3758 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=08b0f791-1700-0000-1be2-d200ae0e0000 pid=3758 execve guuid=bbeaa0ac-1700-0000-1be2-d200f40e0000 pid=3828 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=bbeaa0ac-1700-0000-1be2-d200f40e0000 pid=3828 execve guuid=e2ddf6ca-1700-0000-1be2-d200420f0000 pid=3906 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=e2ddf6ca-1700-0000-1be2-d200420f0000 pid=3906 execve guuid=29d586cb-1700-0000-1be2-d200460f0000 pid=3910 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=29d586cb-1700-0000-1be2-d200460f0000 pid=3910 clone guuid=e8a6ebcb-1700-0000-1be2-d200480f0000 pid=3912 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=e8a6ebcb-1700-0000-1be2-d200480f0000 pid=3912 execve guuid=72bf98cc-1700-0000-1be2-d200490f0000 pid=3913 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=72bf98cc-1700-0000-1be2-d200490f0000 pid=3913 execve guuid=31c10bcd-1700-0000-1be2-d2004b0f0000 pid=3915 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=31c10bcd-1700-0000-1be2-d2004b0f0000 pid=3915 execve guuid=bdeb36e7-1700-0000-1be2-d200840f0000 pid=3972 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=bdeb36e7-1700-0000-1be2-d200840f0000 pid=3972 execve guuid=d62ab302-1800-0000-1be2-d200c80f0000 pid=4040 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=d62ab302-1800-0000-1be2-d200c80f0000 pid=4040 execve guuid=144a4503-1800-0000-1be2-d200c90f0000 pid=4041 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=144a4503-1800-0000-1be2-d200c90f0000 pid=4041 clone guuid=0f49c203-1800-0000-1be2-d200cb0f0000 pid=4043 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=0f49c203-1800-0000-1be2-d200cb0f0000 pid=4043 execve guuid=4f273004-1800-0000-1be2-d200cf0f0000 pid=4047 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=4f273004-1800-0000-1be2-d200cf0f0000 pid=4047 execve guuid=b6dd9804-1800-0000-1be2-d200d00f0000 pid=4048 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=b6dd9804-1800-0000-1be2-d200d00f0000 pid=4048 execve guuid=8a1f951e-1800-0000-1be2-d20007100000 pid=4103 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=8a1f951e-1800-0000-1be2-d20007100000 pid=4103 execve guuid=a60afa3c-1800-0000-1be2-d2004f100000 pid=4175 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=a60afa3c-1800-0000-1be2-d2004f100000 pid=4175 execve guuid=a21e823d-1800-0000-1be2-d20051100000 pid=4177 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=a21e823d-1800-0000-1be2-d20051100000 pid=4177 clone guuid=1298033e-1800-0000-1be2-d20054100000 pid=4180 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=1298033e-1800-0000-1be2-d20054100000 pid=4180 execve guuid=eac3883e-1800-0000-1be2-d20056100000 pid=4182 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=eac3883e-1800-0000-1be2-d20056100000 pid=4182 execve guuid=b263043f-1800-0000-1be2-d20058100000 pid=4184 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=b263043f-1800-0000-1be2-d20058100000 pid=4184 execve guuid=1b4b3759-1800-0000-1be2-d2008f100000 pid=4239 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=1b4b3759-1800-0000-1be2-d2008f100000 pid=4239 execve guuid=7fec9974-1800-0000-1be2-d200d6100000 pid=4310 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=7fec9974-1800-0000-1be2-d200d6100000 pid=4310 execve guuid=340c2875-1800-0000-1be2-d200d8100000 pid=4312 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=340c2875-1800-0000-1be2-d200d8100000 pid=4312 clone guuid=2d9d8c75-1800-0000-1be2-d200dc100000 pid=4316 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=2d9d8c75-1800-0000-1be2-d200dc100000 pid=4316 execve guuid=f7b60a76-1800-0000-1be2-d200dd100000 pid=4317 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=f7b60a76-1800-0000-1be2-d200dd100000 pid=4317 execve guuid=b4017f76-1800-0000-1be2-d200e0100000 pid=4320 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=b4017f76-1800-0000-1be2-d200e0100000 pid=4320 execve guuid=f9e68290-1800-0000-1be2-d2001f110000 pid=4383 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=f9e68290-1800-0000-1be2-d2001f110000 pid=4383 execve guuid=e77bdead-1800-0000-1be2-d2006c110000 pid=4460 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=e77bdead-1800-0000-1be2-d2006c110000 pid=4460 execve guuid=12f28cae-1800-0000-1be2-d2006d110000 pid=4461 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=12f28cae-1800-0000-1be2-d2006d110000 pid=4461 clone guuid=f6f326af-1800-0000-1be2-d20072110000 pid=4466 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=f6f326af-1800-0000-1be2-d20072110000 pid=4466 execve guuid=d6729baf-1800-0000-1be2-d20075110000 pid=4469 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=d6729baf-1800-0000-1be2-d20075110000 pid=4469 execve guuid=188c03b0-1800-0000-1be2-d20077110000 pid=4471 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=188c03b0-1800-0000-1be2-d20077110000 pid=4471 execve guuid=6a1b6cca-1800-0000-1be2-d200c0110000 pid=4544 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=6a1b6cca-1800-0000-1be2-d200c0110000 pid=4544 execve guuid=c32324e7-1800-0000-1be2-d20011120000 pid=4625 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=c32324e7-1800-0000-1be2-d20011120000 pid=4625 execve guuid=661aa7e7-1800-0000-1be2-d20013120000 pid=4627 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=661aa7e7-1800-0000-1be2-d20013120000 pid=4627 clone guuid=136e07e8-1800-0000-1be2-d20018120000 pid=4632 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=136e07e8-1800-0000-1be2-d20018120000 pid=4632 execve guuid=930f6ee8-1800-0000-1be2-d20019120000 pid=4633 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=930f6ee8-1800-0000-1be2-d20019120000 pid=4633 execve guuid=9a1ec9e8-1800-0000-1be2-d2001d120000 pid=4637 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=9a1ec9e8-1800-0000-1be2-d2001d120000 pid=4637 execve guuid=fb95b803-1900-0000-1be2-d20054120000 pid=4692 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=fb95b803-1900-0000-1be2-d20054120000 pid=4692 execve guuid=9e73aa20-1900-0000-1be2-d200a6120000 pid=4774 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=9e73aa20-1900-0000-1be2-d200a6120000 pid=4774 execve guuid=bb3b3f21-1900-0000-1be2-d200a8120000 pid=4776 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=bb3b3f21-1900-0000-1be2-d200a8120000 pid=4776 clone guuid=649fb021-1900-0000-1be2-d200aa120000 pid=4778 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=649fb021-1900-0000-1be2-d200aa120000 pid=4778 execve guuid=f0f33d22-1900-0000-1be2-d200ac120000 pid=4780 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=f0f33d22-1900-0000-1be2-d200ac120000 pid=4780 execve guuid=b15ab622-1900-0000-1be2-d200ae120000 pid=4782 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=b15ab622-1900-0000-1be2-d200ae120000 pid=4782 execve guuid=fa0e353d-1900-0000-1be2-d200e4120000 pid=4836 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=fa0e353d-1900-0000-1be2-d200e4120000 pid=4836 execve guuid=a543865a-1900-0000-1be2-d20023130000 pid=4899 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=a543865a-1900-0000-1be2-d20023130000 pid=4899 execve guuid=c03d075b-1900-0000-1be2-d20025130000 pid=4901 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=c03d075b-1900-0000-1be2-d20025130000 pid=4901 clone guuid=6bb77c5b-1900-0000-1be2-d20028130000 pid=4904 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=6bb77c5b-1900-0000-1be2-d20028130000 pid=4904 execve guuid=1cae045c-1900-0000-1be2-d2002a130000 pid=4906 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=1cae045c-1900-0000-1be2-d2002a130000 pid=4906 execve guuid=81cf835c-1900-0000-1be2-d2002c130000 pid=4908 /usr/bin/wget net send-data guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=81cf835c-1900-0000-1be2-d2002c130000 pid=4908 execve guuid=49077c79-1900-0000-1be2-d20069130000 pid=4969 /usr/bin/curl net send-data write-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=49077c79-1900-0000-1be2-d20069130000 pid=4969 execve guuid=f0e82b98-1900-0000-1be2-d200ac130000 pid=5036 /usr/bin/chmod guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=f0e82b98-1900-0000-1be2-d200ac130000 pid=5036 execve guuid=d0128b98-1900-0000-1be2-d200ad130000 pid=5037 /usr/bin/bash guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=d0128b98-1900-0000-1be2-d200ad130000 pid=5037 clone guuid=99b0d198-1900-0000-1be2-d200b0130000 pid=5040 /usr/bin/rm delete-file guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=99b0d198-1900-0000-1be2-d200b0130000 pid=5040 execve guuid=be134499-1900-0000-1be2-d200b1130000 pid=5041 /usr/bin/rm guuid=789beee3-1600-0000-1be2-d200340d0000 pid=3380->guuid=be134499-1900-0000-1be2-d200b1130000 pid=5041 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=fff149e4-1600-0000-1be2-d200360d0000 pid=3382->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=6ffe4e00-1700-0000-1be2-d2007d0d0000 pid=3453->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3bd01f20-1700-0000-1be2-d200b20d0000 pid=3506 /usr/bin/bash guuid=52c00720-1700-0000-1be2-d200b10d0000 pid=3505->guuid=3bd01f20-1700-0000-1be2-d200b20d0000 pid=3506 clone guuid=ca9b2a21-1700-0000-1be2-d200b90d0000 pid=3513->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=3d503f3b-1700-0000-1be2-d200ee0d0000 pid=3566->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=49172a58-1700-0000-1be2-d200210e0000 pid=3617 /usr/bin/bash guuid=7414fd57-1700-0000-1be2-d200200e0000 pid=3616->guuid=49172a58-1700-0000-1be2-d200210e0000 pid=3617 clone guuid=9a326b59-1700-0000-1be2-d200280e0000 pid=3624->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=23d88073-1700-0000-1be2-d2005c0e0000 pid=3676->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=6917bf90-1700-0000-1be2-d200a80e0000 pid=3752 /usr/bin/bash guuid=df009390-1700-0000-1be2-d200a70e0000 pid=3751->guuid=6917bf90-1700-0000-1be2-d200a80e0000 pid=3752 clone guuid=08b0f791-1700-0000-1be2-d200ae0e0000 pid=3758->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=bbeaa0ac-1700-0000-1be2-d200f40e0000 pid=3828->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=fd14b4cb-1700-0000-1be2-d200470f0000 pid=3911 /usr/bin/bash guuid=29d586cb-1700-0000-1be2-d200460f0000 pid=3910->guuid=fd14b4cb-1700-0000-1be2-d200470f0000 pid=3911 clone guuid=31c10bcd-1700-0000-1be2-d2004b0f0000 pid=3915->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=bdeb36e7-1700-0000-1be2-d200840f0000 pid=3972->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=c7357e03-1800-0000-1be2-d200ca0f0000 pid=4042 /usr/bin/bash guuid=144a4503-1800-0000-1be2-d200c90f0000 pid=4041->guuid=c7357e03-1800-0000-1be2-d200ca0f0000 pid=4042 clone guuid=b6dd9804-1800-0000-1be2-d200d00f0000 pid=4048->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=8a1f951e-1800-0000-1be2-d20007100000 pid=4103->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=301bbd3d-1800-0000-1be2-d20052100000 pid=4178 /usr/bin/bash guuid=a21e823d-1800-0000-1be2-d20051100000 pid=4177->guuid=301bbd3d-1800-0000-1be2-d20052100000 pid=4178 clone guuid=b263043f-1800-0000-1be2-d20058100000 pid=4184->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=1b4b3759-1800-0000-1be2-d2008f100000 pid=4239->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=a1685275-1800-0000-1be2-d200db100000 pid=4315 /usr/bin/bash guuid=340c2875-1800-0000-1be2-d200d8100000 pid=4312->guuid=a1685275-1800-0000-1be2-d200db100000 pid=4315 clone guuid=b4017f76-1800-0000-1be2-d200e0100000 pid=4320->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f9e68290-1800-0000-1be2-d2001f110000 pid=4383->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=9d1ac7ae-1800-0000-1be2-d20070110000 pid=4464 /usr/bin/bash guuid=12f28cae-1800-0000-1be2-d2006d110000 pid=4461->guuid=9d1ac7ae-1800-0000-1be2-d20070110000 pid=4464 clone guuid=188c03b0-1800-0000-1be2-d20077110000 pid=4471->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=6a1b6cca-1800-0000-1be2-d200c0110000 pid=4544->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=7424d2e7-1800-0000-1be2-d20016120000 pid=4630 /usr/bin/bash guuid=661aa7e7-1800-0000-1be2-d20013120000 pid=4627->guuid=7424d2e7-1800-0000-1be2-d20016120000 pid=4630 clone guuid=9a1ec9e8-1800-0000-1be2-d2001d120000 pid=4637->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=fb95b803-1900-0000-1be2-d20054120000 pid=4692->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=0d9c6f21-1900-0000-1be2-d200a9120000 pid=4777 /usr/bin/bash guuid=bb3b3f21-1900-0000-1be2-d200a8120000 pid=4776->guuid=0d9c6f21-1900-0000-1be2-d200a9120000 pid=4777 clone guuid=b15ab622-1900-0000-1be2-d200ae120000 pid=4782->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=fa0e353d-1900-0000-1be2-d200e4120000 pid=4836->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=77a23d5b-1900-0000-1be2-d20026130000 pid=4902 /usr/bin/bash guuid=c03d075b-1900-0000-1be2-d20025130000 pid=4901->guuid=77a23d5b-1900-0000-1be2-d20026130000 pid=4902 clone guuid=81cf835c-1900-0000-1be2-d2002c130000 pid=4908->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=49077c79-1900-0000-1be2-d20069130000 pid=4969->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=1545a998-1900-0000-1be2-d200ae130000 pid=5038 /usr/bin/bash guuid=d0128b98-1900-0000-1be2-d200ad130000 pid=5037->guuid=1545a998-1900-0000-1be2-d200ae130000 pid=5038 clone
Threat name:
Script.Downloader.Malgent
Status:
Malicious
First seen:
2026-06-11 06:10:51 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh decbeefb88f6deda17330f7690eb836ea7cbc915c4790ff6d9716f525e6e473f

(this sample)

  
Delivery method
Distributed via web download

Comments