MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e62ab4b92943ca82c0a8956f59b75cd613fdc8cdd570ad9358eff03c3f9c9d94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: e62ab4b92943ca82c0a8956f59b75cd613fdc8cdd570ad9358eff03c3f9c9d94
SHA3-384 hash: 1989901ad7de0fe61a3177cf0b4872d2a25a941cbde0aa2deedb59d214761cce7bbb72e58851c81952f3de6c859c9ac5
SHA1 hash: b09897129698c56ba79ab92ac9d925f2851e83ca
MD5 hash: 542e600239d6e4e552fec3129697a9ef
humanhash: twenty-winner-kentucky-speaker
File name:1.sh
Download: download sample
File size:6'359 bytes
First seen:2025-08-20 20:37:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:kR3mBzkOBqA/p835YC12MOk7siqgnAGpPOZ7pPOZ7SofI+DNwDV8Gpio+Ur8Snx+:kR3mBzkOBqA/p835YC12MOk7siqgnAG9
TLSH T1BDD12EF2B486627CDD9FCD3A615069BD108ABA8B26874D6887BE20757C89FDC1C41DC3
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mipsn/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arcn/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i468n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i686n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86_64n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mpsln/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.armn/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm5n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm6n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm7n/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.ppcn/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.spcn/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.m68kn/an/aelf ua-wget
http://196.251.73.24/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=92e6bcaa-1600-0000-6812-89a7810c0000 pid=3201 /usr/bin/sudo guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202 /tmp/sample.bin guuid=92e6bcaa-1600-0000-6812-89a7810c0000 pid=3201->guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202 execve guuid=837bf9af-1600-0000-6812-89a7840c0000 pid=3204 /usr/bin/cp guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=837bf9af-1600-0000-6812-89a7840c0000 pid=3204 execve guuid=d182e8b4-1600-0000-6812-89a78f0c0000 pid=3215 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=d182e8b4-1600-0000-6812-89a78f0c0000 pid=3215 execve guuid=6220b7b7-1600-0000-6812-89a7940c0000 pid=3220 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=6220b7b7-1600-0000-6812-89a7940c0000 pid=3220 execve guuid=002e06c0-1600-0000-6812-89a79b0c0000 pid=3227 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=002e06c0-1600-0000-6812-89a79b0c0000 pid=3227 execve guuid=1f9c60c0-1600-0000-6812-89a79c0c0000 pid=3228 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=1f9c60c0-1600-0000-6812-89a79c0c0000 pid=3228 clone guuid=28bb86c0-1600-0000-6812-89a79e0c0000 pid=3230 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=28bb86c0-1600-0000-6812-89a79e0c0000 pid=3230 execve guuid=a6a3cbc0-1600-0000-6812-89a79f0c0000 pid=3231 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=a6a3cbc0-1600-0000-6812-89a79f0c0000 pid=3231 execve guuid=fa34edc3-1600-0000-6812-89a7a60c0000 pid=3238 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=fa34edc3-1600-0000-6812-89a7a60c0000 pid=3238 execve guuid=13d380c7-1600-0000-6812-89a7ae0c0000 pid=3246 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=13d380c7-1600-0000-6812-89a7ae0c0000 pid=3246 execve guuid=fe89c4c7-1600-0000-6812-89a7b00c0000 pid=3248 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=fe89c4c7-1600-0000-6812-89a7b00c0000 pid=3248 clone guuid=ae66ebc7-1600-0000-6812-89a7b10c0000 pid=3249 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=ae66ebc7-1600-0000-6812-89a7b10c0000 pid=3249 execve guuid=f9694bc8-1600-0000-6812-89a7b20c0000 pid=3250 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=f9694bc8-1600-0000-6812-89a7b20c0000 pid=3250 execve guuid=6c9094ca-1600-0000-6812-89a7b90c0000 pid=3257 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=6c9094ca-1600-0000-6812-89a7b90c0000 pid=3257 execve guuid=ca8559ce-1600-0000-6812-89a7ba0c0000 pid=3258 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=ca8559ce-1600-0000-6812-89a7ba0c0000 pid=3258 execve guuid=5eedacce-1600-0000-6812-89a7bc0c0000 pid=3260 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=5eedacce-1600-0000-6812-89a7bc0c0000 pid=3260 clone guuid=1691e6ce-1600-0000-6812-89a7bd0c0000 pid=3261 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=1691e6ce-1600-0000-6812-89a7bd0c0000 pid=3261 execve guuid=14055fcf-1600-0000-6812-89a7be0c0000 pid=3262 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=14055fcf-1600-0000-6812-89a7be0c0000 pid=3262 execve guuid=edbbc9d1-1600-0000-6812-89a7c60c0000 pid=3270 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=edbbc9d1-1600-0000-6812-89a7c60c0000 pid=3270 execve guuid=b8752cd5-1600-0000-6812-89a7d20c0000 pid=3282 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=b8752cd5-1600-0000-6812-89a7d20c0000 pid=3282 execve guuid=f72f76d5-1600-0000-6812-89a7d40c0000 pid=3284 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=f72f76d5-1600-0000-6812-89a7d40c0000 pid=3284 clone guuid=fdf596d5-1600-0000-6812-89a7d50c0000 pid=3285 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=fdf596d5-1600-0000-6812-89a7d50c0000 pid=3285 execve guuid=13f402d6-1600-0000-6812-89a7d70c0000 pid=3287 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=13f402d6-1600-0000-6812-89a7d70c0000 pid=3287 execve guuid=cbf8f0d8-1600-0000-6812-89a7e20c0000 pid=3298 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=cbf8f0d8-1600-0000-6812-89a7e20c0000 pid=3298 execve guuid=b9a4dadd-1600-0000-6812-89a7f10c0000 pid=3313 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=b9a4dadd-1600-0000-6812-89a7f10c0000 pid=3313 execve guuid=6c3c25de-1600-0000-6812-89a7f30c0000 pid=3315 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=6c3c25de-1600-0000-6812-89a7f30c0000 pid=3315 clone guuid=8a8545de-1600-0000-6812-89a7f40c0000 pid=3316 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=8a8545de-1600-0000-6812-89a7f40c0000 pid=3316 execve guuid=46c5a5de-1600-0000-6812-89a7f50c0000 pid=3317 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=46c5a5de-1600-0000-6812-89a7f50c0000 pid=3317 execve guuid=b4f557e1-1600-0000-6812-89a7fb0c0000 pid=3323 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=b4f557e1-1600-0000-6812-89a7fb0c0000 pid=3323 execve guuid=93a4c4e4-1600-0000-6812-89a7040d0000 pid=3332 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=93a4c4e4-1600-0000-6812-89a7040d0000 pid=3332 execve guuid=afd508e5-1600-0000-6812-89a7060d0000 pid=3334 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=afd508e5-1600-0000-6812-89a7060d0000 pid=3334 clone guuid=705033e5-1600-0000-6812-89a7080d0000 pid=3336 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=705033e5-1600-0000-6812-89a7080d0000 pid=3336 execve guuid=516485e5-1600-0000-6812-89a70a0d0000 pid=3338 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=516485e5-1600-0000-6812-89a70a0d0000 pid=3338 execve guuid=ab090ae8-1600-0000-6812-89a7100d0000 pid=3344 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=ab090ae8-1600-0000-6812-89a7100d0000 pid=3344 execve guuid=4046f3eb-1600-0000-6812-89a7150d0000 pid=3349 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=4046f3eb-1600-0000-6812-89a7150d0000 pid=3349 execve guuid=402b97ec-1600-0000-6812-89a7160d0000 pid=3350 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=402b97ec-1600-0000-6812-89a7160d0000 pid=3350 clone guuid=74c6efec-1600-0000-6812-89a7170d0000 pid=3351 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=74c6efec-1600-0000-6812-89a7170d0000 pid=3351 execve guuid=b6aa9fed-1600-0000-6812-89a7180d0000 pid=3352 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=b6aa9fed-1600-0000-6812-89a7180d0000 pid=3352 execve guuid=ea2d0cf1-1600-0000-6812-89a71a0d0000 pid=3354 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=ea2d0cf1-1600-0000-6812-89a71a0d0000 pid=3354 execve guuid=9278acf4-1600-0000-6812-89a7240d0000 pid=3364 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=9278acf4-1600-0000-6812-89a7240d0000 pid=3364 execve guuid=75fb10f5-1600-0000-6812-89a7260d0000 pid=3366 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=75fb10f5-1600-0000-6812-89a7260d0000 pid=3366 clone guuid=b39547f5-1600-0000-6812-89a7270d0000 pid=3367 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=b39547f5-1600-0000-6812-89a7270d0000 pid=3367 execve guuid=7e769df5-1600-0000-6812-89a7290d0000 pid=3369 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=7e769df5-1600-0000-6812-89a7290d0000 pid=3369 execve guuid=33cd4cf8-1600-0000-6812-89a72f0d0000 pid=3375 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=33cd4cf8-1600-0000-6812-89a72f0d0000 pid=3375 execve guuid=a236d0fc-1600-0000-6812-89a7380d0000 pid=3384 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=a236d0fc-1600-0000-6812-89a7380d0000 pid=3384 execve guuid=db7f2efd-1600-0000-6812-89a73a0d0000 pid=3386 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=db7f2efd-1600-0000-6812-89a73a0d0000 pid=3386 clone guuid=d9c453fd-1600-0000-6812-89a73b0d0000 pid=3387 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=d9c453fd-1600-0000-6812-89a73b0d0000 pid=3387 execve guuid=0aaab3fd-1600-0000-6812-89a73c0d0000 pid=3388 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=0aaab3fd-1600-0000-6812-89a73c0d0000 pid=3388 execve guuid=f21d1700-1700-0000-6812-89a7440d0000 pid=3396 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=f21d1700-1700-0000-6812-89a7440d0000 pid=3396 execve guuid=d612ba04-1700-0000-6812-89a7520d0000 pid=3410 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=d612ba04-1700-0000-6812-89a7520d0000 pid=3410 execve guuid=2d73f704-1700-0000-6812-89a7530d0000 pid=3411 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=2d73f704-1700-0000-6812-89a7530d0000 pid=3411 clone guuid=356f1805-1700-0000-6812-89a7550d0000 pid=3413 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=356f1805-1700-0000-6812-89a7550d0000 pid=3413 execve guuid=bf4a6205-1700-0000-6812-89a7570d0000 pid=3415 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=bf4a6205-1700-0000-6812-89a7570d0000 pid=3415 execve guuid=29398a07-1700-0000-6812-89a75e0d0000 pid=3422 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=29398a07-1700-0000-6812-89a75e0d0000 pid=3422 execve guuid=2f2cc90b-1700-0000-6812-89a76d0d0000 pid=3437 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=2f2cc90b-1700-0000-6812-89a76d0d0000 pid=3437 execve guuid=a3f40b0c-1700-0000-6812-89a76f0d0000 pid=3439 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=a3f40b0c-1700-0000-6812-89a76f0d0000 pid=3439 clone guuid=f4e62e0c-1700-0000-6812-89a7710d0000 pid=3441 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=f4e62e0c-1700-0000-6812-89a7710d0000 pid=3441 execve guuid=3f147a0c-1700-0000-6812-89a7730d0000 pid=3443 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=3f147a0c-1700-0000-6812-89a7730d0000 pid=3443 execve guuid=792c1a0f-1700-0000-6812-89a77b0d0000 pid=3451 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=792c1a0f-1700-0000-6812-89a77b0d0000 pid=3451 execve guuid=2c42a413-1700-0000-6812-89a7880d0000 pid=3464 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=2c42a413-1700-0000-6812-89a7880d0000 pid=3464 execve guuid=d320ff13-1700-0000-6812-89a78a0d0000 pid=3466 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=d320ff13-1700-0000-6812-89a78a0d0000 pid=3466 clone guuid=bddc3814-1700-0000-6812-89a78c0d0000 pid=3468 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=bddc3814-1700-0000-6812-89a78c0d0000 pid=3468 execve guuid=76398b14-1700-0000-6812-89a78e0d0000 pid=3470 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=76398b14-1700-0000-6812-89a78e0d0000 pid=3470 execve guuid=fe854817-1700-0000-6812-89a7970d0000 pid=3479 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=fe854817-1700-0000-6812-89a7970d0000 pid=3479 execve guuid=e83f9e1b-1700-0000-6812-89a7a40d0000 pid=3492 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=e83f9e1b-1700-0000-6812-89a7a40d0000 pid=3492 execve guuid=201efc1b-1700-0000-6812-89a7a60d0000 pid=3494 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=201efc1b-1700-0000-6812-89a7a60d0000 pid=3494 clone guuid=87b72d1c-1700-0000-6812-89a7a70d0000 pid=3495 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=87b72d1c-1700-0000-6812-89a7a70d0000 pid=3495 execve guuid=e1918c1c-1700-0000-6812-89a7a90d0000 pid=3497 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=e1918c1c-1700-0000-6812-89a7a90d0000 pid=3497 execve guuid=fa95831f-1700-0000-6812-89a7b20d0000 pid=3506 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=fa95831f-1700-0000-6812-89a7b20d0000 pid=3506 execve guuid=8aa7b723-1700-0000-6812-89a7bf0d0000 pid=3519 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=8aa7b723-1700-0000-6812-89a7bf0d0000 pid=3519 execve guuid=43b41d24-1700-0000-6812-89a7c00d0000 pid=3520 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=43b41d24-1700-0000-6812-89a7c00d0000 pid=3520 clone guuid=99485524-1700-0000-6812-89a7c20d0000 pid=3522 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=99485524-1700-0000-6812-89a7c20d0000 pid=3522 execve guuid=6528b624-1700-0000-6812-89a7c40d0000 pid=3524 /usr/bin/wget net send-data guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=6528b624-1700-0000-6812-89a7c40d0000 pid=3524 execve guuid=30095d27-1700-0000-6812-89a7cc0d0000 pid=3532 /usr/bin/curl net send-data write-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=30095d27-1700-0000-6812-89a7cc0d0000 pid=3532 execve guuid=efc5c12a-1700-0000-6812-89a7da0d0000 pid=3546 /usr/bin/chmod guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=efc5c12a-1700-0000-6812-89a7da0d0000 pid=3546 execve guuid=eda0042b-1700-0000-6812-89a7dc0d0000 pid=3548 /usr/bin/bash guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=eda0042b-1700-0000-6812-89a7dc0d0000 pid=3548 clone guuid=5a1a382b-1700-0000-6812-89a7dd0d0000 pid=3549 /usr/bin/rm delete-file guuid=b24070ae-1600-0000-6812-89a7820c0000 pid=3202->guuid=5a1a382b-1700-0000-6812-89a7dd0d0000 pid=3549 execve 6beadc35-efc4-5e26-84e6-0089cd490f0e 196.251.73.24:80 guuid=d182e8b4-1600-0000-6812-89a78f0c0000 pid=3215->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 213B guuid=6220b7b7-1600-0000-6812-89a7940c0000 pid=3220->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 162B guuid=a6a3cbc0-1600-0000-6812-89a79f0c0000 pid=3231->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=fa34edc3-1600-0000-6812-89a7a60c0000 pid=3238->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=f9694bc8-1600-0000-6812-89a7b20c0000 pid=3250->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 213B guuid=6c9094ca-1600-0000-6812-89a7b90c0000 pid=3257->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 162B guuid=14055fcf-1600-0000-6812-89a7be0c0000 pid=3262->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=edbbc9d1-1600-0000-6812-89a7c60c0000 pid=3270->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=13f402d6-1600-0000-6812-89a7d70c0000 pid=3287->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=cbf8f0d8-1600-0000-6812-89a7e20c0000 pid=3298->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=46c5a5de-1600-0000-6812-89a7f50c0000 pid=3317->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 216B guuid=b4f557e1-1600-0000-6812-89a7fb0c0000 pid=3323->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 165B guuid=516485e5-1600-0000-6812-89a70a0d0000 pid=3338->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=ab090ae8-1600-0000-6812-89a7100d0000 pid=3344->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=b6aa9fed-1600-0000-6812-89a7180d0000 pid=3352->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 213B guuid=ea2d0cf1-1600-0000-6812-89a71a0d0000 pid=3354->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 162B guuid=7e769df5-1600-0000-6812-89a7290d0000 pid=3369->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=33cd4cf8-1600-0000-6812-89a72f0d0000 pid=3375->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=0aaab3fd-1600-0000-6812-89a73c0d0000 pid=3388->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=f21d1700-1700-0000-6812-89a7440d0000 pid=3396->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=bf4a6205-1700-0000-6812-89a7570d0000 pid=3415->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=29398a07-1700-0000-6812-89a75e0d0000 pid=3422->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=3f147a0c-1700-0000-6812-89a7730d0000 pid=3443->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 213B guuid=792c1a0f-1700-0000-6812-89a77b0d0000 pid=3451->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 162B guuid=76398b14-1700-0000-6812-89a78e0d0000 pid=3470->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 213B guuid=fe854817-1700-0000-6812-89a7970d0000 pid=3479->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 162B guuid=e1918c1c-1700-0000-6812-89a7a90d0000 pid=3497->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 214B guuid=fa95831f-1700-0000-6812-89a7b20d0000 pid=3506->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 163B guuid=6528b624-1700-0000-6812-89a7c40d0000 pid=3524->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 213B guuid=30095d27-1700-0000-6812-89a7cc0d0000 pid=3532->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 162B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-08-20 20:38:34 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e62ab4b92943ca82c0a8956f59b75cd613fdc8cdd570ad9358eff03c3f9c9d94

(this sample)

  
Delivery method
Distributed via web download

Comments