MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5493e88fb7092b0901a08153447e43e52d8053ec5484e48b9f3ba09c4a4841f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: e5493e88fb7092b0901a08153447e43e52d8053ec5484e48b9f3ba09c4a4841f
SHA3-384 hash: 0a66f010d9c1f4e21583e9bc84b57cb91eb8bdf9c90ef7319fb264fa7e78c5803169f6e1547254e8c766986dcb30634c
SHA1 hash: 89aceaafdb182a0434d7e7eb5011728831105a51
MD5 hash: e4ae9c1e9e62bed65867ead59be36fbb
humanhash: princess-emma-edward-alanine
File name:ok
Download: download sample
File size:1'608 bytes
First seen:2026-06-09 20:40:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:5sLrsxItpfr1bJefJB1BP7r1Bg6TIZXrZ+btXRyIrRy08hR42pSrpCVyarozlYg2:U4Dgfd+/R+nk8azvPNjiXyA0oX
TLSH T10831B6AB4B193D9D5401E979376124D8E464E7CE205FE3D4FF980CBB96C91483249B0F
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=1d7b3b7b-1900-0000-8d85-c872c30d0000 pid=3523 /usr/bin/sudo guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525 /tmp/sample.bin guuid=1d7b3b7b-1900-0000-8d85-c872c30d0000 pid=3523->guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525 execve guuid=1e13e17e-1900-0000-8d85-c872c60d0000 pid=3526 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=1e13e17e-1900-0000-8d85-c872c60d0000 pid=3526 execve guuid=e3b6e89b-1900-0000-8d85-c872010e0000 pid=3585 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=e3b6e89b-1900-0000-8d85-c872010e0000 pid=3585 execve guuid=0a1870bc-1900-0000-8d85-c872410e0000 pid=3649 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=0a1870bc-1900-0000-8d85-c872410e0000 pid=3649 execve guuid=8047fdbc-1900-0000-8d85-c872450e0000 pid=3653 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=8047fdbc-1900-0000-8d85-c872450e0000 pid=3653 clone guuid=eef571bd-1900-0000-8d85-c872490e0000 pid=3657 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=eef571bd-1900-0000-8d85-c872490e0000 pid=3657 execve guuid=e3e9febd-1900-0000-8d85-c8724b0e0000 pid=3659 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=e3e9febd-1900-0000-8d85-c8724b0e0000 pid=3659 execve guuid=29e287be-1900-0000-8d85-c8724d0e0000 pid=3661 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=29e287be-1900-0000-8d85-c8724d0e0000 pid=3661 execve guuid=bea69bdb-1900-0000-8d85-c872780e0000 pid=3704 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=bea69bdb-1900-0000-8d85-c872780e0000 pid=3704 execve guuid=ffbf29fa-1900-0000-8d85-c872e50e0000 pid=3813 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=ffbf29fa-1900-0000-8d85-c872e50e0000 pid=3813 execve guuid=e32d72fa-1900-0000-8d85-c872e70e0000 pid=3815 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=e32d72fa-1900-0000-8d85-c872e70e0000 pid=3815 clone guuid=3493acfa-1900-0000-8d85-c872eb0e0000 pid=3819 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=3493acfa-1900-0000-8d85-c872eb0e0000 pid=3819 execve guuid=cc0efdfa-1900-0000-8d85-c872ed0e0000 pid=3821 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=cc0efdfa-1900-0000-8d85-c872ed0e0000 pid=3821 execve guuid=c35964fb-1900-0000-8d85-c872f00e0000 pid=3824 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=c35964fb-1900-0000-8d85-c872f00e0000 pid=3824 execve guuid=7c021518-1a00-0000-8d85-c872470f0000 pid=3911 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=7c021518-1a00-0000-8d85-c872470f0000 pid=3911 execve guuid=6ffd2137-1a00-0000-8d85-c872910f0000 pid=3985 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=6ffd2137-1a00-0000-8d85-c872910f0000 pid=3985 execve guuid=a154bf37-1a00-0000-8d85-c872930f0000 pid=3987 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=a154bf37-1a00-0000-8d85-c872930f0000 pid=3987 clone guuid=f1522438-1a00-0000-8d85-c872970f0000 pid=3991 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=f1522438-1a00-0000-8d85-c872970f0000 pid=3991 execve guuid=8ccfe038-1a00-0000-8d85-c872980f0000 pid=3992 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=8ccfe038-1a00-0000-8d85-c872980f0000 pid=3992 execve guuid=8a298539-1a00-0000-8d85-c8729b0f0000 pid=3995 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=8a298539-1a00-0000-8d85-c8729b0f0000 pid=3995 execve guuid=84dfb456-1a00-0000-8d85-c872e30f0000 pid=4067 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=84dfb456-1a00-0000-8d85-c872e30f0000 pid=4067 execve guuid=8cf4ef74-1a00-0000-8d85-c87241100000 pid=4161 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=8cf4ef74-1a00-0000-8d85-c87241100000 pid=4161 execve guuid=872f5d75-1a00-0000-8d85-c87243100000 pid=4163 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=872f5d75-1a00-0000-8d85-c87243100000 pid=4163 clone guuid=a0e7a375-1a00-0000-8d85-c87245100000 pid=4165 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=a0e7a375-1a00-0000-8d85-c87245100000 pid=4165 execve guuid=da630076-1a00-0000-8d85-c87247100000 pid=4167 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=da630076-1a00-0000-8d85-c87247100000 pid=4167 execve guuid=1a3f5176-1a00-0000-8d85-c87249100000 pid=4169 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=1a3f5176-1a00-0000-8d85-c87249100000 pid=4169 execve guuid=3f7ae691-1a00-0000-8d85-c87289100000 pid=4233 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=3f7ae691-1a00-0000-8d85-c87289100000 pid=4233 execve guuid=f7a43cb0-1a00-0000-8d85-c872d6100000 pid=4310 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=f7a43cb0-1a00-0000-8d85-c872d6100000 pid=4310 execve guuid=4d6096b0-1a00-0000-8d85-c872d8100000 pid=4312 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=4d6096b0-1a00-0000-8d85-c872d8100000 pid=4312 clone guuid=2ad6d4b0-1a00-0000-8d85-c872db100000 pid=4315 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=2ad6d4b0-1a00-0000-8d85-c872db100000 pid=4315 execve guuid=20b924b1-1a00-0000-8d85-c872dd100000 pid=4317 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=20b924b1-1a00-0000-8d85-c872dd100000 pid=4317 execve guuid=caf994b1-1a00-0000-8d85-c872df100000 pid=4319 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=caf994b1-1a00-0000-8d85-c872df100000 pid=4319 execve guuid=116681cd-1a00-0000-8d85-c87212110000 pid=4370 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=116681cd-1a00-0000-8d85-c87212110000 pid=4370 execve guuid=c4c09deb-1a00-0000-8d85-c87261110000 pid=4449 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=c4c09deb-1a00-0000-8d85-c87261110000 pid=4449 execve guuid=5961eaeb-1a00-0000-8d85-c87263110000 pid=4451 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=5961eaeb-1a00-0000-8d85-c87263110000 pid=4451 clone guuid=f16626ec-1a00-0000-8d85-c87266110000 pid=4454 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=f16626ec-1a00-0000-8d85-c87266110000 pid=4454 execve guuid=dada78ec-1a00-0000-8d85-c87268110000 pid=4456 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=dada78ec-1a00-0000-8d85-c87268110000 pid=4456 execve guuid=3f6cd1ec-1a00-0000-8d85-c8726a110000 pid=4458 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=3f6cd1ec-1a00-0000-8d85-c8726a110000 pid=4458 execve guuid=b4c55e08-1b00-0000-8d85-c872c0110000 pid=4544 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=b4c55e08-1b00-0000-8d85-c872c0110000 pid=4544 execve guuid=50fbf028-1b00-0000-8d85-c87223120000 pid=4643 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=50fbf028-1b00-0000-8d85-c87223120000 pid=4643 execve guuid=b9c47a29-1b00-0000-8d85-c87224120000 pid=4644 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=b9c47a29-1b00-0000-8d85-c87224120000 pid=4644 clone guuid=3702e329-1b00-0000-8d85-c87227120000 pid=4647 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=3702e329-1b00-0000-8d85-c87227120000 pid=4647 execve guuid=d031742a-1b00-0000-8d85-c87229120000 pid=4649 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=d031742a-1b00-0000-8d85-c87229120000 pid=4649 execve guuid=94d1e72a-1b00-0000-8d85-c8722b120000 pid=4651 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=94d1e72a-1b00-0000-8d85-c8722b120000 pid=4651 execve guuid=74366247-1b00-0000-8d85-c87265120000 pid=4709 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=74366247-1b00-0000-8d85-c87265120000 pid=4709 execve guuid=722af664-1b00-0000-8d85-c872b0120000 pid=4784 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=722af664-1b00-0000-8d85-c872b0120000 pid=4784 execve guuid=c47f5c65-1b00-0000-8d85-c872b1120000 pid=4785 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=c47f5c65-1b00-0000-8d85-c872b1120000 pid=4785 clone guuid=0e43c465-1b00-0000-8d85-c872b4120000 pid=4788 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=0e43c465-1b00-0000-8d85-c872b4120000 pid=4788 execve guuid=7a372666-1b00-0000-8d85-c872b7120000 pid=4791 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=7a372666-1b00-0000-8d85-c872b7120000 pid=4791 execve guuid=50de8166-1b00-0000-8d85-c872b9120000 pid=4793 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=50de8166-1b00-0000-8d85-c872b9120000 pid=4793 execve guuid=b34f7b82-1b00-0000-8d85-c872fe120000 pid=4862 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=b34f7b82-1b00-0000-8d85-c872fe120000 pid=4862 execve guuid=7c10e6a0-1b00-0000-8d85-c8723f130000 pid=4927 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=7c10e6a0-1b00-0000-8d85-c8723f130000 pid=4927 execve guuid=16ba8ca1-1b00-0000-8d85-c87241130000 pid=4929 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=16ba8ca1-1b00-0000-8d85-c87241130000 pid=4929 clone guuid=ee0c12a2-1b00-0000-8d85-c87244130000 pid=4932 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=ee0c12a2-1b00-0000-8d85-c87244130000 pid=4932 execve guuid=49f7a2a2-1b00-0000-8d85-c87247130000 pid=4935 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=49f7a2a2-1b00-0000-8d85-c87247130000 pid=4935 execve guuid=55a52da3-1b00-0000-8d85-c87249130000 pid=4937 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=55a52da3-1b00-0000-8d85-c87249130000 pid=4937 execve guuid=b89f89bf-1b00-0000-8d85-c8728a130000 pid=5002 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=b89f89bf-1b00-0000-8d85-c8728a130000 pid=5002 execve guuid=44790ddc-1b00-0000-8d85-c872da130000 pid=5082 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=44790ddc-1b00-0000-8d85-c872da130000 pid=5082 execve guuid=f0aa90dc-1b00-0000-8d85-c872db130000 pid=5083 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=f0aa90dc-1b00-0000-8d85-c872db130000 pid=5083 clone guuid=36271bdd-1b00-0000-8d85-c872e0130000 pid=5088 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=36271bdd-1b00-0000-8d85-c872e0130000 pid=5088 execve guuid=dee58cdd-1b00-0000-8d85-c872e4130000 pid=5092 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=dee58cdd-1b00-0000-8d85-c872e4130000 pid=5092 execve guuid=210deddd-1b00-0000-8d85-c872e5130000 pid=5093 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=210deddd-1b00-0000-8d85-c872e5130000 pid=5093 execve guuid=e462f0f9-1b00-0000-8d85-c87230140000 pid=5168 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=e462f0f9-1b00-0000-8d85-c87230140000 pid=5168 execve guuid=1559df17-1c00-0000-8d85-c87253140000 pid=5203 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=1559df17-1c00-0000-8d85-c87253140000 pid=5203 execve guuid=81d5cc18-1c00-0000-8d85-c87256140000 pid=5206 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=81d5cc18-1c00-0000-8d85-c87256140000 pid=5206 clone guuid=1be16819-1c00-0000-8d85-c87259140000 pid=5209 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=1be16819-1c00-0000-8d85-c87259140000 pid=5209 execve guuid=f55ff219-1c00-0000-8d85-c8725a140000 pid=5210 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=f55ff219-1c00-0000-8d85-c8725a140000 pid=5210 execve guuid=7e32621a-1c00-0000-8d85-c8725c140000 pid=5212 /usr/bin/wget net send-data guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=7e32621a-1c00-0000-8d85-c8725c140000 pid=5212 execve guuid=495c2436-1c00-0000-8d85-c8729f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=495c2436-1c00-0000-8d85-c8729f140000 pid=5279 execve guuid=1f059853-1c00-0000-8d85-c872b7140000 pid=5303 /usr/bin/chmod guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=1f059853-1c00-0000-8d85-c872b7140000 pid=5303 execve guuid=0f262154-1c00-0000-8d85-c872b8140000 pid=5304 /usr/bin/bash guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=0f262154-1c00-0000-8d85-c872b8140000 pid=5304 clone guuid=dc219454-1c00-0000-8d85-c872ba140000 pid=5306 /usr/bin/rm delete-file guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=dc219454-1c00-0000-8d85-c872ba140000 pid=5306 execve guuid=3aa11d55-1c00-0000-8d85-c872bb140000 pid=5307 /usr/bin/rm guuid=b1e3337e-1900-0000-8d85-c872c50d0000 pid=3525->guuid=3aa11d55-1c00-0000-8d85-c872bb140000 pid=5307 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=1e13e17e-1900-0000-8d85-c872c60d0000 pid=3526->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=e3b6e89b-1900-0000-8d85-c872010e0000 pid=3585->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=309d2bbd-1900-0000-8d85-c872460e0000 pid=3654 /usr/bin/bash guuid=8047fdbc-1900-0000-8d85-c872450e0000 pid=3653->guuid=309d2bbd-1900-0000-8d85-c872460e0000 pid=3654 clone guuid=29e287be-1900-0000-8d85-c8724d0e0000 pid=3661->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=bea69bdb-1900-0000-8d85-c872780e0000 pid=3704->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=db1c91fa-1900-0000-8d85-c872ea0e0000 pid=3818 /usr/bin/bash guuid=e32d72fa-1900-0000-8d85-c872e70e0000 pid=3815->guuid=db1c91fa-1900-0000-8d85-c872ea0e0000 pid=3818 clone guuid=c35964fb-1900-0000-8d85-c872f00e0000 pid=3824->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=7c021518-1a00-0000-8d85-c872470f0000 pid=3911->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=4845e737-1a00-0000-8d85-c872960f0000 pid=3990 /usr/bin/bash guuid=a154bf37-1a00-0000-8d85-c872930f0000 pid=3987->guuid=4845e737-1a00-0000-8d85-c872960f0000 pid=3990 clone guuid=8a298539-1a00-0000-8d85-c8729b0f0000 pid=3995->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=84dfb456-1a00-0000-8d85-c872e30f0000 pid=4067->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d4aa7f75-1a00-0000-8d85-c87244100000 pid=4164 /usr/bin/bash guuid=872f5d75-1a00-0000-8d85-c87243100000 pid=4163->guuid=d4aa7f75-1a00-0000-8d85-c87244100000 pid=4164 clone guuid=1a3f5176-1a00-0000-8d85-c87249100000 pid=4169->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=3f7ae691-1a00-0000-8d85-c87289100000 pid=4233->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=337bb5b0-1a00-0000-8d85-c872d9100000 pid=4313 /usr/bin/bash guuid=4d6096b0-1a00-0000-8d85-c872d8100000 pid=4312->guuid=337bb5b0-1a00-0000-8d85-c872d9100000 pid=4313 clone guuid=caf994b1-1a00-0000-8d85-c872df100000 pid=4319->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=116681cd-1a00-0000-8d85-c87212110000 pid=4370->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=f79907ec-1a00-0000-8d85-c87264110000 pid=4452 /usr/bin/bash guuid=5961eaeb-1a00-0000-8d85-c87263110000 pid=4451->guuid=f79907ec-1a00-0000-8d85-c87264110000 pid=4452 clone guuid=3f6cd1ec-1a00-0000-8d85-c8726a110000 pid=4458->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b4c55e08-1b00-0000-8d85-c872c0110000 pid=4544->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=869ba929-1b00-0000-8d85-c87226120000 pid=4646 /usr/bin/bash guuid=b9c47a29-1b00-0000-8d85-c87224120000 pid=4644->guuid=869ba929-1b00-0000-8d85-c87226120000 pid=4646 clone guuid=94d1e72a-1b00-0000-8d85-c8722b120000 pid=4651->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=74366247-1b00-0000-8d85-c87265120000 pid=4709->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=5dde8365-1b00-0000-8d85-c872b3120000 pid=4787 /usr/bin/bash guuid=c47f5c65-1b00-0000-8d85-c872b1120000 pid=4785->guuid=5dde8365-1b00-0000-8d85-c872b3120000 pid=4787 clone guuid=50de8166-1b00-0000-8d85-c872b9120000 pid=4793->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b34f7b82-1b00-0000-8d85-c872fe120000 pid=4862->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=34b4d1a1-1b00-0000-8d85-c87243130000 pid=4931 /usr/bin/bash guuid=16ba8ca1-1b00-0000-8d85-c87241130000 pid=4929->guuid=34b4d1a1-1b00-0000-8d85-c87243130000 pid=4931 clone guuid=55a52da3-1b00-0000-8d85-c87249130000 pid=4937->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b89f89bf-1b00-0000-8d85-c8728a130000 pid=5002->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=82d8bcdc-1b00-0000-8d85-c872dc130000 pid=5084 /usr/bin/bash guuid=f0aa90dc-1b00-0000-8d85-c872db130000 pid=5083->guuid=82d8bcdc-1b00-0000-8d85-c872dc130000 pid=5084 clone guuid=210deddd-1b00-0000-8d85-c872e5130000 pid=5093->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=e462f0f9-1b00-0000-8d85-c87230140000 pid=5168->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d2872319-1c00-0000-8d85-c87257140000 pid=5207 /usr/bin/bash guuid=81d5cc18-1c00-0000-8d85-c87256140000 pid=5206->guuid=d2872319-1c00-0000-8d85-c87257140000 pid=5207 clone guuid=7e32621a-1c00-0000-8d85-c8725c140000 pid=5212->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=495c2436-1c00-0000-8d85-c8729f140000 pid=5279->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=df055454-1c00-0000-8d85-c872b9140000 pid=5305 /usr/bin/bash guuid=0f262154-1c00-0000-8d85-c872b8140000 pid=5304->guuid=df055454-1c00-0000-8d85-c872b9140000 pid=5305 clone
Threat name:
Script.Downloader.Malgent
Status:
Malicious
First seen:
2026-06-09 20:41:31 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e5493e88fb7092b0901a08153447e43e52d8053ec5484e48b9f3ba09c4a4841f

(this sample)

  
Delivery method
Distributed via web download

Comments