MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e7b6143633d06de3917f52fc50dd7b932a452feade27235fddd4bf42f0dea650. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: e7b6143633d06de3917f52fc50dd7b932a452feade27235fddd4bf42f0dea650
SHA3-384 hash: d4a81dae23e03d93a9f7706218927b3ff712bbdc9ba057dffc743bc824c56234961c437f41d11f40ad605e7e13cc1616
SHA1 hash: 5e72c46023820ba23d0033e13eda9f45c4f27b3a
MD5 hash: 9c1701c84e6ef723ba66359e72a0889e
humanhash: california-charlie-dakota-connecticut
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-23 09:05:46 UTC
Last seen:2026-06-23 22:50:26 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UYi6YsA6VL6VaO+dudW6Exx61jw6ngvp/MsD6A466AQ9P9lR6sIAf6J66EtdBni2:9qs9dO/Jdxfdx4MQe0WV
TLSH T185314DDE40105A382202C9DEB763364CE04C85EB2D97D798C9581FED96C86CCB252BD9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/f0a1b9n/an/aelf ua-wget
http://5.182.210.61/1a70a3n/an/aelf ua-wget
http://5.182.210.61/030d34n/an/aelf ua-wget
http://5.182.210.61/c20310n/an/aelf ua-wget
http://5.182.210.61/3475cdn/an/aelf ua-wget
http://5.182.210.61/b78de2n/an/aelf ua-wget
http://5.182.210.61/a14535n/an/aelf ua-wget
http://5.182.210.61/1de7f2n/an/aelf ua-wget
http://5.182.210.61/068dd6n/an/aelf ua-wget
http://5.182.210.61/6d4385n/an/aelf ua-wget
http://5.182.210.61/d5891fn/an/aelf ua-wget
http://5.182.210.61/b2ac87n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-23T06:23:00Z UTC
Last seen:
2026-06-23T08:39:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c447da6d-1900-0000-ea0d-2a7d33140000 pid=5171 /usr/bin/sudo guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172 /tmp/sample.bin guuid=c447da6d-1900-0000-ea0d-2a7d33140000 pid=5171->guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172 execve guuid=3d549274-1900-0000-ea0d-2a7d35140000 pid=5173 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=3d549274-1900-0000-ea0d-2a7d35140000 pid=5173 execve guuid=c884657f-1900-0000-ea0d-2a7d36140000 pid=5174 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=c884657f-1900-0000-ea0d-2a7d36140000 pid=5174 execve guuid=910e888d-1900-0000-ea0d-2a7d37140000 pid=5175 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=910e888d-1900-0000-ea0d-2a7d37140000 pid=5175 execve guuid=5c0b408e-1900-0000-ea0d-2a7d38140000 pid=5176 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=5c0b408e-1900-0000-ea0d-2a7d38140000 pid=5176 clone guuid=88e63c8f-1900-0000-ea0d-2a7d3a140000 pid=5178 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=88e63c8f-1900-0000-ea0d-2a7d3a140000 pid=5178 execve guuid=022ae08f-1900-0000-ea0d-2a7d3b140000 pid=5179 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=022ae08f-1900-0000-ea0d-2a7d3b140000 pid=5179 execve guuid=00ab6390-1900-0000-ea0d-2a7d3c140000 pid=5180 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=00ab6390-1900-0000-ea0d-2a7d3c140000 pid=5180 execve guuid=bf49ea94-1900-0000-ea0d-2a7d3d140000 pid=5181 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=bf49ea94-1900-0000-ea0d-2a7d3d140000 pid=5181 execve guuid=7b91d49b-1900-0000-ea0d-2a7d3e140000 pid=5182 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=7b91d49b-1900-0000-ea0d-2a7d3e140000 pid=5182 execve guuid=d10b4e9c-1900-0000-ea0d-2a7d3f140000 pid=5183 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=d10b4e9c-1900-0000-ea0d-2a7d3f140000 pid=5183 clone guuid=8ffa049d-1900-0000-ea0d-2a7d41140000 pid=5185 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=8ffa049d-1900-0000-ea0d-2a7d41140000 pid=5185 execve guuid=9e16519d-1900-0000-ea0d-2a7d42140000 pid=5186 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=9e16519d-1900-0000-ea0d-2a7d42140000 pid=5186 execve guuid=cb06bb9d-1900-0000-ea0d-2a7d43140000 pid=5187 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=cb06bb9d-1900-0000-ea0d-2a7d43140000 pid=5187 execve guuid=2302d6a0-1900-0000-ea0d-2a7d44140000 pid=5188 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=2302d6a0-1900-0000-ea0d-2a7d44140000 pid=5188 execve guuid=8c1a63a8-1900-0000-ea0d-2a7d45140000 pid=5189 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=8c1a63a8-1900-0000-ea0d-2a7d45140000 pid=5189 execve guuid=bd67f1a8-1900-0000-ea0d-2a7d46140000 pid=5190 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=bd67f1a8-1900-0000-ea0d-2a7d46140000 pid=5190 clone guuid=d50bb1a9-1900-0000-ea0d-2a7d48140000 pid=5192 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=d50bb1a9-1900-0000-ea0d-2a7d48140000 pid=5192 execve guuid=36705eaa-1900-0000-ea0d-2a7d49140000 pid=5193 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=36705eaa-1900-0000-ea0d-2a7d49140000 pid=5193 execve guuid=f4e31dab-1900-0000-ea0d-2a7d4a140000 pid=5194 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=f4e31dab-1900-0000-ea0d-2a7d4a140000 pid=5194 execve guuid=d939e7ae-1900-0000-ea0d-2a7d4b140000 pid=5195 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=d939e7ae-1900-0000-ea0d-2a7d4b140000 pid=5195 execve guuid=64fbcab4-1900-0000-ea0d-2a7d4c140000 pid=5196 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=64fbcab4-1900-0000-ea0d-2a7d4c140000 pid=5196 execve guuid=7f9d47b5-1900-0000-ea0d-2a7d4d140000 pid=5197 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=7f9d47b5-1900-0000-ea0d-2a7d4d140000 pid=5197 clone guuid=8509e9b5-1900-0000-ea0d-2a7d4f140000 pid=5199 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=8509e9b5-1900-0000-ea0d-2a7d4f140000 pid=5199 execve guuid=ca0b47b6-1900-0000-ea0d-2a7d50140000 pid=5200 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=ca0b47b6-1900-0000-ea0d-2a7d50140000 pid=5200 execve guuid=f07d85b6-1900-0000-ea0d-2a7d51140000 pid=5201 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=f07d85b6-1900-0000-ea0d-2a7d51140000 pid=5201 execve guuid=600e0fba-1900-0000-ea0d-2a7d52140000 pid=5202 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=600e0fba-1900-0000-ea0d-2a7d52140000 pid=5202 execve guuid=dacc63bf-1900-0000-ea0d-2a7d53140000 pid=5203 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=dacc63bf-1900-0000-ea0d-2a7d53140000 pid=5203 execve guuid=4bc1b0bf-1900-0000-ea0d-2a7d54140000 pid=5204 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=4bc1b0bf-1900-0000-ea0d-2a7d54140000 pid=5204 clone guuid=88cee1bf-1900-0000-ea0d-2a7d56140000 pid=5206 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=88cee1bf-1900-0000-ea0d-2a7d56140000 pid=5206 execve guuid=707128c0-1900-0000-ea0d-2a7d57140000 pid=5207 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=707128c0-1900-0000-ea0d-2a7d57140000 pid=5207 execve guuid=96e96ac0-1900-0000-ea0d-2a7d58140000 pid=5208 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=96e96ac0-1900-0000-ea0d-2a7d58140000 pid=5208 execve guuid=6442edc2-1900-0000-ea0d-2a7d59140000 pid=5209 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=6442edc2-1900-0000-ea0d-2a7d59140000 pid=5209 execve guuid=f90672c6-1900-0000-ea0d-2a7d5a140000 pid=5210 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=f90672c6-1900-0000-ea0d-2a7d5a140000 pid=5210 execve guuid=e8c2b9c6-1900-0000-ea0d-2a7d5b140000 pid=5211 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=e8c2b9c6-1900-0000-ea0d-2a7d5b140000 pid=5211 clone guuid=aceb0fc7-1900-0000-ea0d-2a7d5d140000 pid=5213 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=aceb0fc7-1900-0000-ea0d-2a7d5d140000 pid=5213 execve guuid=ecee5ec7-1900-0000-ea0d-2a7d5e140000 pid=5214 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=ecee5ec7-1900-0000-ea0d-2a7d5e140000 pid=5214 execve guuid=21bfa0c7-1900-0000-ea0d-2a7d5f140000 pid=5215 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=21bfa0c7-1900-0000-ea0d-2a7d5f140000 pid=5215 execve guuid=879942ca-1900-0000-ea0d-2a7d60140000 pid=5216 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=879942ca-1900-0000-ea0d-2a7d60140000 pid=5216 execve guuid=8c4bf4cd-1900-0000-ea0d-2a7d61140000 pid=5217 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=8c4bf4cd-1900-0000-ea0d-2a7d61140000 pid=5217 execve guuid=9acc46ce-1900-0000-ea0d-2a7d62140000 pid=5218 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=9acc46ce-1900-0000-ea0d-2a7d62140000 pid=5218 clone guuid=efeeacce-1900-0000-ea0d-2a7d64140000 pid=5220 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=efeeacce-1900-0000-ea0d-2a7d64140000 pid=5220 execve guuid=74d708cf-1900-0000-ea0d-2a7d65140000 pid=5221 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=74d708cf-1900-0000-ea0d-2a7d65140000 pid=5221 execve guuid=c42c60cf-1900-0000-ea0d-2a7d66140000 pid=5222 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=c42c60cf-1900-0000-ea0d-2a7d66140000 pid=5222 execve guuid=8e0c38d2-1900-0000-ea0d-2a7d67140000 pid=5223 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=8e0c38d2-1900-0000-ea0d-2a7d67140000 pid=5223 execve guuid=55da85d5-1900-0000-ea0d-2a7d68140000 pid=5224 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=55da85d5-1900-0000-ea0d-2a7d68140000 pid=5224 execve guuid=5b3ecdd5-1900-0000-ea0d-2a7d69140000 pid=5225 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=5b3ecdd5-1900-0000-ea0d-2a7d69140000 pid=5225 clone guuid=470820d6-1900-0000-ea0d-2a7d6b140000 pid=5227 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=470820d6-1900-0000-ea0d-2a7d6b140000 pid=5227 execve guuid=250a81d6-1900-0000-ea0d-2a7d6c140000 pid=5228 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=250a81d6-1900-0000-ea0d-2a7d6c140000 pid=5228 execve guuid=07d0d5d6-1900-0000-ea0d-2a7d6d140000 pid=5229 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=07d0d5d6-1900-0000-ea0d-2a7d6d140000 pid=5229 execve guuid=54a66ed9-1900-0000-ea0d-2a7d6f140000 pid=5231 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=54a66ed9-1900-0000-ea0d-2a7d6f140000 pid=5231 execve guuid=a772cedc-1900-0000-ea0d-2a7d70140000 pid=5232 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=a772cedc-1900-0000-ea0d-2a7d70140000 pid=5232 execve guuid=addd0edd-1900-0000-ea0d-2a7d71140000 pid=5233 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=addd0edd-1900-0000-ea0d-2a7d71140000 pid=5233 clone guuid=423346dd-1900-0000-ea0d-2a7d73140000 pid=5235 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=423346dd-1900-0000-ea0d-2a7d73140000 pid=5235 execve guuid=a0f085dd-1900-0000-ea0d-2a7d74140000 pid=5236 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=a0f085dd-1900-0000-ea0d-2a7d74140000 pid=5236 execve guuid=ab96c2dd-1900-0000-ea0d-2a7d75140000 pid=5237 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=ab96c2dd-1900-0000-ea0d-2a7d75140000 pid=5237 execve guuid=4fd737e0-1900-0000-ea0d-2a7d76140000 pid=5238 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=4fd737e0-1900-0000-ea0d-2a7d76140000 pid=5238 execve guuid=17e860f2-1900-0000-ea0d-2a7d7c140000 pid=5244 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=17e860f2-1900-0000-ea0d-2a7d7c140000 pid=5244 execve guuid=478ab1f2-1900-0000-ea0d-2a7d7d140000 pid=5245 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=478ab1f2-1900-0000-ea0d-2a7d7d140000 pid=5245 clone guuid=551b5df3-1900-0000-ea0d-2a7d7f140000 pid=5247 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=551b5df3-1900-0000-ea0d-2a7d7f140000 pid=5247 execve guuid=368fbff3-1900-0000-ea0d-2a7d80140000 pid=5248 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=368fbff3-1900-0000-ea0d-2a7d80140000 pid=5248 execve guuid=05802af4-1900-0000-ea0d-2a7d81140000 pid=5249 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=05802af4-1900-0000-ea0d-2a7d81140000 pid=5249 execve guuid=c58cc9f6-1900-0000-ea0d-2a7d86140000 pid=5254 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=c58cc9f6-1900-0000-ea0d-2a7d86140000 pid=5254 execve guuid=eaf5fafa-1900-0000-ea0d-2a7d8a140000 pid=5258 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=eaf5fafa-1900-0000-ea0d-2a7d8a140000 pid=5258 execve guuid=b98544fb-1900-0000-ea0d-2a7d8b140000 pid=5259 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=b98544fb-1900-0000-ea0d-2a7d8b140000 pid=5259 clone guuid=65138cfb-1900-0000-ea0d-2a7d8d140000 pid=5261 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=65138cfb-1900-0000-ea0d-2a7d8d140000 pid=5261 execve guuid=16d9cefb-1900-0000-ea0d-2a7d8e140000 pid=5262 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=16d9cefb-1900-0000-ea0d-2a7d8e140000 pid=5262 execve guuid=0f8225fc-1900-0000-ea0d-2a7d8f140000 pid=5263 /usr/bin/wget net send-data guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=0f8225fc-1900-0000-ea0d-2a7d8f140000 pid=5263 execve guuid=c71c8afe-1900-0000-ea0d-2a7d90140000 pid=5264 /usr/bin/curl net send-data write-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=c71c8afe-1900-0000-ea0d-2a7d90140000 pid=5264 execve guuid=79b90602-1a00-0000-ea0d-2a7d91140000 pid=5265 /usr/bin/chmod guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=79b90602-1a00-0000-ea0d-2a7d91140000 pid=5265 execve guuid=a74b4b02-1a00-0000-ea0d-2a7d92140000 pid=5266 /usr/bin/bash guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=a74b4b02-1a00-0000-ea0d-2a7d92140000 pid=5266 clone guuid=3c079602-1a00-0000-ea0d-2a7d94140000 pid=5268 /usr/bin/rm delete-file guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=3c079602-1a00-0000-ea0d-2a7d94140000 pid=5268 execve guuid=9968dc02-1a00-0000-ea0d-2a7d95140000 pid=5269 /usr/bin/rm guuid=b6262373-1900-0000-ea0d-2a7d34140000 pid=5172->guuid=9968dc02-1a00-0000-ea0d-2a7d95140000 pid=5269 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=3d549274-1900-0000-ea0d-2a7d35140000 pid=5173->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=c884657f-1900-0000-ea0d-2a7d36140000 pid=5174->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=b9e3938e-1900-0000-ea0d-2a7d39140000 pid=5177 /usr/bin/bash guuid=5c0b408e-1900-0000-ea0d-2a7d38140000 pid=5176->guuid=b9e3938e-1900-0000-ea0d-2a7d39140000 pid=5177 clone guuid=00ab6390-1900-0000-ea0d-2a7d3c140000 pid=5180->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=bf49ea94-1900-0000-ea0d-2a7d3d140000 pid=5181->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e03b659c-1900-0000-ea0d-2a7d40140000 pid=5184 /usr/bin/bash guuid=d10b4e9c-1900-0000-ea0d-2a7d3f140000 pid=5183->guuid=e03b659c-1900-0000-ea0d-2a7d40140000 pid=5184 clone guuid=cb06bb9d-1900-0000-ea0d-2a7d43140000 pid=5187->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=2302d6a0-1900-0000-ea0d-2a7d44140000 pid=5188->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=78ed44a9-1900-0000-ea0d-2a7d47140000 pid=5191 /usr/bin/bash guuid=bd67f1a8-1900-0000-ea0d-2a7d46140000 pid=5190->guuid=78ed44a9-1900-0000-ea0d-2a7d47140000 pid=5191 clone guuid=f4e31dab-1900-0000-ea0d-2a7d4a140000 pid=5194->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=d939e7ae-1900-0000-ea0d-2a7d4b140000 pid=5195->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=8fa3abb5-1900-0000-ea0d-2a7d4e140000 pid=5198 /usr/bin/bash guuid=7f9d47b5-1900-0000-ea0d-2a7d4d140000 pid=5197->guuid=8fa3abb5-1900-0000-ea0d-2a7d4e140000 pid=5198 clone guuid=f07d85b6-1900-0000-ea0d-2a7d51140000 pid=5201->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=600e0fba-1900-0000-ea0d-2a7d52140000 pid=5202->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=7910c5bf-1900-0000-ea0d-2a7d55140000 pid=5205 /usr/bin/bash guuid=4bc1b0bf-1900-0000-ea0d-2a7d54140000 pid=5204->guuid=7910c5bf-1900-0000-ea0d-2a7d55140000 pid=5205 clone guuid=96e96ac0-1900-0000-ea0d-2a7d58140000 pid=5208->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=6442edc2-1900-0000-ea0d-2a7d59140000 pid=5209->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=6da0ebc6-1900-0000-ea0d-2a7d5c140000 pid=5212 /usr/bin/bash guuid=e8c2b9c6-1900-0000-ea0d-2a7d5b140000 pid=5211->guuid=6da0ebc6-1900-0000-ea0d-2a7d5c140000 pid=5212 clone guuid=21bfa0c7-1900-0000-ea0d-2a7d5f140000 pid=5215->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=879942ca-1900-0000-ea0d-2a7d60140000 pid=5216->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=617e6cce-1900-0000-ea0d-2a7d63140000 pid=5219 /usr/bin/bash guuid=9acc46ce-1900-0000-ea0d-2a7d62140000 pid=5218->guuid=617e6cce-1900-0000-ea0d-2a7d63140000 pid=5219 clone guuid=c42c60cf-1900-0000-ea0d-2a7d66140000 pid=5222->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=8e0c38d2-1900-0000-ea0d-2a7d67140000 pid=5223->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=cd19e5d5-1900-0000-ea0d-2a7d6a140000 pid=5226 /usr/bin/bash guuid=5b3ecdd5-1900-0000-ea0d-2a7d69140000 pid=5225->guuid=cd19e5d5-1900-0000-ea0d-2a7d6a140000 pid=5226 clone guuid=07d0d5d6-1900-0000-ea0d-2a7d6d140000 pid=5229->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=54a66ed9-1900-0000-ea0d-2a7d6f140000 pid=5231->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=faec25dd-1900-0000-ea0d-2a7d72140000 pid=5234 /usr/bin/bash guuid=addd0edd-1900-0000-ea0d-2a7d71140000 pid=5233->guuid=faec25dd-1900-0000-ea0d-2a7d72140000 pid=5234 clone guuid=ab96c2dd-1900-0000-ea0d-2a7d75140000 pid=5237->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=4fd737e0-1900-0000-ea0d-2a7d76140000 pid=5238->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=d5b408f3-1900-0000-ea0d-2a7d7e140000 pid=5246 /usr/bin/bash guuid=478ab1f2-1900-0000-ea0d-2a7d7d140000 pid=5245->guuid=d5b408f3-1900-0000-ea0d-2a7d7e140000 pid=5246 clone guuid=05802af4-1900-0000-ea0d-2a7d81140000 pid=5249->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=c58cc9f6-1900-0000-ea0d-2a7d86140000 pid=5254->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=dbe75ffb-1900-0000-ea0d-2a7d8c140000 pid=5260 /usr/bin/bash guuid=b98544fb-1900-0000-ea0d-2a7d8b140000 pid=5259->guuid=dbe75ffb-1900-0000-ea0d-2a7d8c140000 pid=5260 clone guuid=0f8225fc-1900-0000-ea0d-2a7d8f140000 pid=5263->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=c71c8afe-1900-0000-ea0d-2a7d90140000 pid=5264->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=50416902-1a00-0000-ea0d-2a7d93140000 pid=5267 /usr/bin/bash guuid=a74b4b02-1a00-0000-ea0d-2a7d92140000 pid=5266->guuid=50416902-1a00-0000-ea0d-2a7d93140000 pid=5267 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-06-23 09:06:31 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e7b6143633d06de3917f52fc50dd7b932a452feade27235fddd4bf42f0dea650

(this sample)

  
Delivery method
Distributed via web download

Comments