MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5cd8594072a0acdb295d18ca3e64687fa7df5446e52b7ba72a1f75f9795666d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e5cd8594072a0acdb295d18ca3e64687fa7df5446e52b7ba72a1f75f9795666d
SHA3-384 hash: f411e9a8df671f8cf7f131feb7989186f5abe30d79859a28131238edf17f951c2d702230f7cb81335457e59e821a7914
SHA1 hash: 9549221fd8cb48a7f11a359ac7773c6df4531722
MD5 hash: 75a9ec8231b8e6082708a161c706ca4f
humanhash: stairway-zebra-april-king
File name:linux_ak.sh
Download: download sample
File size:1'972 bytes
First seen:2026-05-11 22:31:16 UTC
Last seen:2026-05-12 00:26:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:aSBvN2ufHMzQKFGXx3wSTEYLHvHpO8OSI4QiY2Xx30XW8:/vN2ufM+EXZW8
TLSH T1CF414C4E4F46D0E1628024FC674F3986B88715FF92158104F79EBB8BAFB4711E2989DB
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-11T19:38:00Z UTC
Last seen:
2026-05-12T12:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=f24dd8e4-1900-0000-142d-e24f43080000 pid=2115 /usr/bin/sudo guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120 /tmp/sample.bin guuid=f24dd8e4-1900-0000-142d-e24f43080000 pid=2115->guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120 execve guuid=2fbe20e8-1900-0000-142d-e24f4a080000 pid=2122 /usr/bin/dash guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=2fbe20e8-1900-0000-142d-e24f4a080000 pid=2122 clone guuid=6b2ddde8-1900-0000-142d-e24f4d080000 pid=2125 /usr/bin/dash guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=6b2ddde8-1900-0000-142d-e24f4d080000 pid=2125 clone guuid=432f50e9-1900-0000-142d-e24f50080000 pid=2128 /usr/bin/rm guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=432f50e9-1900-0000-142d-e24f50080000 pid=2128 execve guuid=f166ade9-1900-0000-142d-e24f52080000 pid=2130 /usr/bin/wget net send-data write-file guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=f166ade9-1900-0000-142d-e24f52080000 pid=2130 execve guuid=4760a027-2100-0000-142d-e24f73140000 pid=5235 /usr/bin/chmod guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=4760a027-2100-0000-142d-e24f73140000 pid=5235 execve guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236 /home/sandbox/linux_amd64 zombie guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236 execve guuid=abd88428-2100-0000-142d-e24f75140000 pid=5237 /usr/bin/dash guuid=5c3dcce7-1900-0000-142d-e24f48080000 pid=2120->guuid=abd88428-2100-0000-142d-e24f75140000 pid=5237 clone guuid=e9b12ce8-1900-0000-142d-e24f4b080000 pid=2123 /usr/bin/uname guuid=2fbe20e8-1900-0000-142d-e24f4a080000 pid=2122->guuid=e9b12ce8-1900-0000-142d-e24f4b080000 pid=2123 execve guuid=f50be4e8-1900-0000-142d-e24f4e080000 pid=2126 /usr/bin/uname guuid=6b2ddde8-1900-0000-142d-e24f4d080000 pid=2125->guuid=f50be4e8-1900-0000-142d-e24f4e080000 pid=2126 execve d315db92-aead-5a78-84ac-c7d355badc69 156.238.242.196:80 guuid=f166ade9-1900-0000-142d-e24f52080000 pid=2130->d315db92-aead-5a78-84ac-c7d355badc69 send: 141B guuid=0a447928-2100-0000-142d-e24f74140000 pid=5239 /home/sandbox/linux_amd64 zombie guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236->guuid=0a447928-2100-0000-142d-e24f74140000 pid=5239 clone guuid=0a447928-2100-0000-142d-e24f74140000 pid=5240 /home/sandbox/linux_amd64 guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236->guuid=0a447928-2100-0000-142d-e24f74140000 pid=5240 clone guuid=0a447928-2100-0000-142d-e24f74140000 pid=5241 /home/sandbox/linux_amd64 guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236->guuid=0a447928-2100-0000-142d-e24f74140000 pid=5241 clone guuid=0a447928-2100-0000-142d-e24f74140000 pid=5242 /home/sandbox/linux_amd64 guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236->guuid=0a447928-2100-0000-142d-e24f74140000 pid=5242 clone guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243 /home/sandbox/linux_amd64 delete-file write-config write-file zombie guuid=0a447928-2100-0000-142d-e24f74140000 pid=5236->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243 execve guuid=07bab628-2100-0000-142d-e24f76140000 pid=5238 /usr/bin/sleep guuid=abd88428-2100-0000-142d-e24f75140000 pid=5237->guuid=07bab628-2100-0000-142d-e24f76140000 pid=5238 execve guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5244 /home/sandbox/linux_amd64 zombie guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5244 clone guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5245 /home/sandbox/linux_amd64 guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5245 clone guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5246 /home/sandbox/linux_amd64 dns net send-data zombie guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5246 clone guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5247 /home/sandbox/linux_amd64 dns net send-data zombie guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5247 clone guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248 /home/sandbox/linux_amd64 delete-file send-data write-config write-file zombie guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248 clone guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5249 /home/sandbox/linux_amd64 zombie guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5243->guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5249 clone 1587f3f2-bbce-5218-958c-1dc50cb35907 ak.504.su:28588 guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5246->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 278B guuid=7e07d47e-2100-0000-142d-e24f98140000 pid=5272 /usr/bin/uname guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5246->guuid=7e07d47e-2100-0000-142d-e24f98140000 pid=5272 execve guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5247->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 239B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5247->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->1587f3f2-bbce-5218-958c-1dc50cb35907 send: 43B guuid=f3c41751-2100-0000-142d-e24f82140000 pid=5250 /usr/bin/dash guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=f3c41751-2100-0000-142d-e24f82140000 pid=5250 execve guuid=095dcb51-2100-0000-142d-e24f84140000 pid=5252 /usr/bin/systemctl guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=095dcb51-2100-0000-142d-e24f84140000 pid=5252 execve guuid=e4b033a6-2100-0000-142d-e24f9b140000 pid=5275 /usr/bin/systemctl guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=e4b033a6-2100-0000-142d-e24f9b140000 pid=5275 execve guuid=83ed9ecd-2100-0000-142d-e24fb0140000 pid=5296 /usr/bin/systemctl guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=83ed9ecd-2100-0000-142d-e24fb0140000 pid=5296 execve guuid=564a00dc-2100-0000-142d-e24fbb140000 pid=5307 /usr/sbin/update-rc.d guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=564a00dc-2100-0000-142d-e24fbb140000 pid=5307 execve guuid=8e3ff525-2200-0000-142d-e24fdd140000 pid=5341 /usr/sbin/update-rc.d guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=8e3ff525-2200-0000-142d-e24fdd140000 pid=5341 execve guuid=318fa045-2200-0000-142d-e24ff9140000 pid=5369 /etc/init.d/systemd-logind guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=318fa045-2200-0000-142d-e24ff9140000 pid=5369 execve guuid=01e23d4e-2200-0000-142d-e24f0b150000 pid=5387 /usr/bin/dash guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=01e23d4e-2200-0000-142d-e24f0b150000 pid=5387 execve guuid=69f68d4e-2200-0000-142d-e24f0e150000 pid=5390 /usr/sbin/update-rc.d guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=69f68d4e-2200-0000-142d-e24f0e150000 pid=5390 execve guuid=3413a871-2200-0000-142d-e24f29150000 pid=5417 /usr/sbin/update-rc.d guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=3413a871-2200-0000-142d-e24f29150000 pid=5417 execve guuid=46670292-2200-0000-142d-e24f40150000 pid=5440 /etc/init.d/network-manger guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=46670292-2200-0000-142d-e24f40150000 pid=5440 execve guuid=1c621897-2200-0000-142d-e24f46150000 pid=5446 /usr/bin/dash guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=1c621897-2200-0000-142d-e24f46150000 pid=5446 execve guuid=35218997-2200-0000-142d-e24f48150000 pid=5448 /usr/sbin/update-rc.d guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=35218997-2200-0000-142d-e24f48150000 pid=5448 execve guuid=8e7a67b4-2200-0000-142d-e24f5f150000 pid=5471 /usr/sbin/update-rc.d guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=8e7a67b4-2200-0000-142d-e24f5f150000 pid=5471 execve guuid=c5544fd4-2200-0000-142d-e24f76150000 pid=5494 /etc/init.d/udev-teriger-net guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=c5544fd4-2200-0000-142d-e24f76150000 pid=5494 execve guuid=e47b5dd7-2200-0000-142d-e24f7d150000 pid=5501 /usr/bin/dash guuid=0350c22e-2100-0000-142d-e24f7b140000 pid=5248->guuid=e47b5dd7-2200-0000-142d-e24f7d150000 pid=5501 execve guuid=7f219351-2100-0000-142d-e24f83140000 pid=5251 /boot/System zombie guuid=f3c41751-2100-0000-142d-e24f82140000 pid=5250->guuid=7f219351-2100-0000-142d-e24f83140000 pid=5251 execve guuid=15d1e651-2100-0000-142d-e24f85140000 pid=5253 /usr/bin/sleep guuid=7f219351-2100-0000-142d-e24f83140000 pid=5251->guuid=15d1e651-2100-0000-142d-e24f85140000 pid=5253 execve guuid=16bffddd-2100-0000-142d-e24fbe140000 pid=5310 /usr/bin/systemctl guuid=564a00dc-2100-0000-142d-e24fbb140000 pid=5307->guuid=16bffddd-2100-0000-142d-e24fbe140000 pid=5310 execve guuid=23df4427-2200-0000-142d-e24fe0140000 pid=5344 /usr/bin/systemctl guuid=8e3ff525-2200-0000-142d-e24fdd140000 pid=5341->guuid=23df4427-2200-0000-142d-e24fe0140000 pid=5344 execve guuid=368c4c28-2200-0000-142d-e24fe1140000 pid=5345 /usr/bin/systemctl guuid=8e3ff525-2200-0000-142d-e24fdd140000 pid=5341->guuid=368c4c28-2200-0000-142d-e24fe1140000 pid=5345 execve guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370 /boot/System.img-6.8.0-8 delete-file write-file guuid=318fa045-2200-0000-142d-e24ff9140000 pid=5369->guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370 execve guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5379 /boot/System.img-6.8.0-8 guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370->guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5379 clone guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5380 /boot/System.img-6.8.0-8 guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370->guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5380 clone guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5381 /boot/System.img-6.8.0-8 guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370->guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5381 clone guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5382 /boot/System.img-6.8.0-8 guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370->guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5382 clone guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5383 /boot/System.img-6.8.0-8 guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5370->guuid=2a20d245-2200-0000-142d-e24ffa140000 pid=5383 clone guuid=a717734e-2200-0000-142d-e24f0d150000 pid=5389 /rootfs-ext/bin/killai zombie guuid=01e23d4e-2200-0000-142d-e24f0b150000 pid=5387->guuid=a717734e-2200-0000-142d-e24f0d150000 pid=5389 execve guuid=0cebba4e-2200-0000-142d-e24f0f150000 pid=5391 /usr/bin/sleep guuid=a717734e-2200-0000-142d-e24f0d150000 pid=5389->guuid=0cebba4e-2200-0000-142d-e24f0f150000 pid=5391 execve guuid=e7431c50-2200-0000-142d-e24f13150000 pid=5395 /usr/bin/systemctl guuid=69f68d4e-2200-0000-142d-e24f0e150000 pid=5390->guuid=e7431c50-2200-0000-142d-e24f13150000 pid=5395 execve guuid=41c1dd72-2200-0000-142d-e24f2a150000 pid=5418 /usr/bin/systemctl guuid=3413a871-2200-0000-142d-e24f29150000 pid=5417->guuid=41c1dd72-2200-0000-142d-e24f2a150000 pid=5418 execve guuid=76090b75-2200-0000-142d-e24f2b150000 pid=5419 /usr/bin/systemctl guuid=3413a871-2200-0000-142d-e24f29150000 pid=5417->guuid=76090b75-2200-0000-142d-e24f2b150000 pid=5419 execve guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5441 /rootfs-ext/sbin/nginx-1 delete-file write-file guuid=46670292-2200-0000-142d-e24f40150000 pid=5440->guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5441 execve guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5442 /rootfs-ext/sbin/nginx-1 guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5441->guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5442 clone guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5443 /rootfs-ext/sbin/nginx-1 guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5441->guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5443 clone guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5444 /rootfs-ext/sbin/nginx-1 guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5441->guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5444 clone guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5445 /rootfs-ext/sbin/nginx-1 guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5441->guuid=f0be2d92-2200-0000-142d-e24f41150000 pid=5445 clone guuid=92a36697-2200-0000-142d-e24f47150000 pid=5447 /usr/sbin/.at.atloy zombie guuid=1c621897-2200-0000-142d-e24f46150000 pid=5446->guuid=92a36697-2200-0000-142d-e24f47150000 pid=5447 execve guuid=4cf4ca97-2200-0000-142d-e24f49150000 pid=5449 /usr/bin/sleep guuid=92a36697-2200-0000-142d-e24f47150000 pid=5447->guuid=4cf4ca97-2200-0000-142d-e24f49150000 pid=5449 execve guuid=73a0af98-2200-0000-142d-e24f4a150000 pid=5450 /usr/bin/systemctl guuid=35218997-2200-0000-142d-e24f48150000 pid=5448->guuid=73a0af98-2200-0000-142d-e24f4a150000 pid=5450 execve guuid=730a9cb5-2200-0000-142d-e24f60150000 pid=5472 /usr/bin/systemctl guuid=8e7a67b4-2200-0000-142d-e24f5f150000 pid=5471->guuid=730a9cb5-2200-0000-142d-e24f60150000 pid=5472 execve guuid=38db8fb7-2200-0000-142d-e24f61150000 pid=5473 /usr/bin/systemctl guuid=8e7a67b4-2200-0000-142d-e24f5f150000 pid=5471->guuid=38db8fb7-2200-0000-142d-e24f61150000 pid=5473 execve guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495 /usr/lib/id.sericer.conf delete-file write-file guuid=c5544fd4-2200-0000-142d-e24f76150000 pid=5494->guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495 execve guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5496 /usr/lib/id.sericer.conf guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495->guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5496 clone guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5497 /usr/lib/id.sericer.conf guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495->guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5497 clone guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5498 /usr/lib/id.sericer.conf guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495->guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5498 clone guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5499 /usr/lib/id.sericer.conf guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495->guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5499 clone guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5500 /usr/lib/id.sericer.conf guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5495->guuid=66da7dd4-2200-0000-142d-e24f77150000 pid=5500 clone guuid=66808bd7-2200-0000-142d-e24f7e150000 pid=5502 /tmp/.font-unix-helpver zombie guuid=e47b5dd7-2200-0000-142d-e24f7d150000 pid=5501->guuid=66808bd7-2200-0000-142d-e24f7e150000 pid=5502 execve guuid=4d97c5d7-2200-0000-142d-e24f7f150000 pid=5503 /usr/bin/sleep guuid=66808bd7-2200-0000-142d-e24f7e150000 pid=5502->guuid=4d97c5d7-2200-0000-142d-e24f7f150000 pid=5503 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-11 22:31:54 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Modifies Bash startup script
Enumerates running processes
Modifies init.d
Modifies rc script
Reads list of loaded kernel modules
Write file to user bin folder
Creates/modifies Cron job
Creates/modifies environment variables
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e5cd8594072a0acdb295d18ca3e64687fa7df5446e52b7ba72a1f75f9795666d

(this sample)

  
Delivery method
Distributed via web download

Comments