MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb2d5d13129b28a8250dfdd4c04001ffc888f7903bbf0a10c155eac8eebbb42c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: eb2d5d13129b28a8250dfdd4c04001ffc888f7903bbf0a10c155eac8eebbb42c
SHA3-384 hash: 5901cf7eca85d3de9027106ed506365bbdf346d0d54d39017f6d41eb13f0222fd35b79d5eb17f8992a988a7fc6be3a0f
SHA1 hash: 3ebaa92b86e2a71d44bed2edea757eba7e990d4a
MD5 hash: 1985eee3c393f665b8b9f5da716eab7b
humanhash: maine-magazine-river-lithium
File name:ok
Download: download sample
File size:1'584 bytes
First seen:2026-06-19 14:38:44 UTC
Last seen:2026-06-19 14:58:42 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:3w3sGXQG5K0F6Mx6Qjtjo9Bk5xipgeGl0Zpt3Y:NGk0QwJov8o2eU0Zc
TLSH T13D316EDF44095A395207C9CEB3723158750C82FB288BC7D4DC4C0EAA8688ADC7295BDD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=da06d154-1900-0000-cf29-6a962c140000 pid=5164 /usr/bin/sudo guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165 /tmp/sample.bin guuid=da06d154-1900-0000-cf29-6a962c140000 pid=5164->guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165 execve guuid=f865c557-1900-0000-cf29-6a962e140000 pid=5166 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=f865c557-1900-0000-cf29-6a962e140000 pid=5166 execve guuid=9d41a984-1900-0000-cf29-6a962f140000 pid=5167 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=9d41a984-1900-0000-cf29-6a962f140000 pid=5167 execve guuid=fc3113c1-1900-0000-cf29-6a9630140000 pid=5168 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=fc3113c1-1900-0000-cf29-6a9630140000 pid=5168 execve guuid=3e656cc1-1900-0000-cf29-6a9631140000 pid=5169 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=3e656cc1-1900-0000-cf29-6a9631140000 pid=5169 clone guuid=443ecec1-1900-0000-cf29-6a9633140000 pid=5171 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=443ecec1-1900-0000-cf29-6a9633140000 pid=5171 execve guuid=5ac31ec2-1900-0000-cf29-6a9634140000 pid=5172 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=5ac31ec2-1900-0000-cf29-6a9634140000 pid=5172 execve guuid=796699c2-1900-0000-cf29-6a9635140000 pid=5173 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=796699c2-1900-0000-cf29-6a9635140000 pid=5173 execve guuid=7bd835c5-1900-0000-cf29-6a9636140000 pid=5174 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=7bd835c5-1900-0000-cf29-6a9636140000 pid=5174 execve guuid=540adacb-1900-0000-cf29-6a9637140000 pid=5175 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=540adacb-1900-0000-cf29-6a9637140000 pid=5175 execve guuid=d99c2dcc-1900-0000-cf29-6a9638140000 pid=5176 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=d99c2dcc-1900-0000-cf29-6a9638140000 pid=5176 clone guuid=697498cc-1900-0000-cf29-6a963a140000 pid=5178 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=697498cc-1900-0000-cf29-6a963a140000 pid=5178 execve guuid=a2b0e8cc-1900-0000-cf29-6a963b140000 pid=5179 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=a2b0e8cc-1900-0000-cf29-6a963b140000 pid=5179 execve guuid=590f3bcd-1900-0000-cf29-6a963c140000 pid=5180 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=590f3bcd-1900-0000-cf29-6a963c140000 pid=5180 execve guuid=cde8cbcf-1900-0000-cf29-6a963d140000 pid=5181 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=cde8cbcf-1900-0000-cf29-6a963d140000 pid=5181 execve guuid=571f65d3-1900-0000-cf29-6a963e140000 pid=5182 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=571f65d3-1900-0000-cf29-6a963e140000 pid=5182 execve guuid=a1b1afd3-1900-0000-cf29-6a963f140000 pid=5183 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=a1b1afd3-1900-0000-cf29-6a963f140000 pid=5183 clone guuid=f60efcd3-1900-0000-cf29-6a9641140000 pid=5185 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=f60efcd3-1900-0000-cf29-6a9641140000 pid=5185 execve guuid=16414dd4-1900-0000-cf29-6a9642140000 pid=5186 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=16414dd4-1900-0000-cf29-6a9642140000 pid=5186 execve guuid=fe5094d4-1900-0000-cf29-6a9643140000 pid=5187 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=fe5094d4-1900-0000-cf29-6a9643140000 pid=5187 execve guuid=ca671fd7-1900-0000-cf29-6a9644140000 pid=5188 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=ca671fd7-1900-0000-cf29-6a9644140000 pid=5188 execve guuid=cae09dda-1900-0000-cf29-6a9645140000 pid=5189 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=cae09dda-1900-0000-cf29-6a9645140000 pid=5189 execve guuid=f552edda-1900-0000-cf29-6a9646140000 pid=5190 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=f552edda-1900-0000-cf29-6a9646140000 pid=5190 clone guuid=53712adb-1900-0000-cf29-6a9648140000 pid=5192 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=53712adb-1900-0000-cf29-6a9648140000 pid=5192 execve guuid=82887ddb-1900-0000-cf29-6a9649140000 pid=5193 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=82887ddb-1900-0000-cf29-6a9649140000 pid=5193 execve guuid=523accdb-1900-0000-cf29-6a964a140000 pid=5194 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=523accdb-1900-0000-cf29-6a964a140000 pid=5194 execve guuid=65844dde-1900-0000-cf29-6a964b140000 pid=5195 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=65844dde-1900-0000-cf29-6a964b140000 pid=5195 execve guuid=8a07cce1-1900-0000-cf29-6a964c140000 pid=5196 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=8a07cce1-1900-0000-cf29-6a964c140000 pid=5196 execve guuid=56631ee2-1900-0000-cf29-6a964d140000 pid=5197 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=56631ee2-1900-0000-cf29-6a964d140000 pid=5197 clone guuid=b87574e2-1900-0000-cf29-6a964f140000 pid=5199 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=b87574e2-1900-0000-cf29-6a964f140000 pid=5199 execve guuid=ef31c4e2-1900-0000-cf29-6a9650140000 pid=5200 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=ef31c4e2-1900-0000-cf29-6a9650140000 pid=5200 execve guuid=64fd0ae3-1900-0000-cf29-6a9651140000 pid=5201 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=64fd0ae3-1900-0000-cf29-6a9651140000 pid=5201 execve guuid=45b09de5-1900-0000-cf29-6a9652140000 pid=5202 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=45b09de5-1900-0000-cf29-6a9652140000 pid=5202 execve guuid=1486adec-1900-0000-cf29-6a9653140000 pid=5203 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=1486adec-1900-0000-cf29-6a9653140000 pid=5203 execve guuid=e152ffec-1900-0000-cf29-6a9654140000 pid=5204 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=e152ffec-1900-0000-cf29-6a9654140000 pid=5204 clone guuid=726766ed-1900-0000-cf29-6a9656140000 pid=5206 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=726766ed-1900-0000-cf29-6a9656140000 pid=5206 execve guuid=8458bfed-1900-0000-cf29-6a9657140000 pid=5207 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=8458bfed-1900-0000-cf29-6a9657140000 pid=5207 execve guuid=ded112ee-1900-0000-cf29-6a9658140000 pid=5208 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=ded112ee-1900-0000-cf29-6a9658140000 pid=5208 execve guuid=0546a8f0-1900-0000-cf29-6a9659140000 pid=5209 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=0546a8f0-1900-0000-cf29-6a9659140000 pid=5209 execve guuid=7df064f4-1900-0000-cf29-6a965a140000 pid=5210 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=7df064f4-1900-0000-cf29-6a965a140000 pid=5210 execve guuid=3fceb4f4-1900-0000-cf29-6a965b140000 pid=5211 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=3fceb4f4-1900-0000-cf29-6a965b140000 pid=5211 clone guuid=ed7d10f5-1900-0000-cf29-6a965d140000 pid=5213 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=ed7d10f5-1900-0000-cf29-6a965d140000 pid=5213 execve guuid=e7d764f5-1900-0000-cf29-6a965e140000 pid=5214 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=e7d764f5-1900-0000-cf29-6a965e140000 pid=5214 execve guuid=a62fb7f5-1900-0000-cf29-6a965f140000 pid=5215 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=a62fb7f5-1900-0000-cf29-6a965f140000 pid=5215 execve guuid=21af57f8-1900-0000-cf29-6a9660140000 pid=5216 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=21af57f8-1900-0000-cf29-6a9660140000 pid=5216 execve guuid=483e85fc-1900-0000-cf29-6a9661140000 pid=5217 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=483e85fc-1900-0000-cf29-6a9661140000 pid=5217 execve guuid=c26be6fc-1900-0000-cf29-6a9662140000 pid=5218 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=c26be6fc-1900-0000-cf29-6a9662140000 pid=5218 clone guuid=126c3bfd-1900-0000-cf29-6a9664140000 pid=5220 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=126c3bfd-1900-0000-cf29-6a9664140000 pid=5220 execve guuid=2ad58afd-1900-0000-cf29-6a9665140000 pid=5221 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=2ad58afd-1900-0000-cf29-6a9665140000 pid=5221 execve guuid=9f8acdfd-1900-0000-cf29-6a9666140000 pid=5222 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=9f8acdfd-1900-0000-cf29-6a9666140000 pid=5222 execve guuid=9da3f900-1a00-0000-cf29-6a9667140000 pid=5223 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=9da3f900-1a00-0000-cf29-6a9667140000 pid=5223 execve guuid=c7f69f06-1a00-0000-cf29-6a9668140000 pid=5224 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=c7f69f06-1a00-0000-cf29-6a9668140000 pid=5224 execve guuid=4a935607-1a00-0000-cf29-6a9669140000 pid=5225 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=4a935607-1a00-0000-cf29-6a9669140000 pid=5225 clone guuid=30bca107-1a00-0000-cf29-6a966b140000 pid=5227 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=30bca107-1a00-0000-cf29-6a966b140000 pid=5227 execve guuid=8f0df907-1a00-0000-cf29-6a966c140000 pid=5228 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=8f0df907-1a00-0000-cf29-6a966c140000 pid=5228 execve guuid=14374f08-1a00-0000-cf29-6a966d140000 pid=5229 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=14374f08-1a00-0000-cf29-6a966d140000 pid=5229 execve guuid=4d03fc0a-1a00-0000-cf29-6a966e140000 pid=5230 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=4d03fc0a-1a00-0000-cf29-6a966e140000 pid=5230 execve guuid=0a92db0e-1a00-0000-cf29-6a966f140000 pid=5231 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=0a92db0e-1a00-0000-cf29-6a966f140000 pid=5231 execve guuid=28f24f0f-1a00-0000-cf29-6a9670140000 pid=5232 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=28f24f0f-1a00-0000-cf29-6a9670140000 pid=5232 clone guuid=e00eaf0f-1a00-0000-cf29-6a9672140000 pid=5234 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=e00eaf0f-1a00-0000-cf29-6a9672140000 pid=5234 execve guuid=f9fa1810-1a00-0000-cf29-6a9673140000 pid=5235 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=f9fa1810-1a00-0000-cf29-6a9673140000 pid=5235 execve guuid=0a7a7a10-1a00-0000-cf29-6a9674140000 pid=5236 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=0a7a7a10-1a00-0000-cf29-6a9674140000 pid=5236 execve guuid=0dd25113-1a00-0000-cf29-6a9675140000 pid=5237 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=0dd25113-1a00-0000-cf29-6a9675140000 pid=5237 execve guuid=a47f3417-1a00-0000-cf29-6a9676140000 pid=5238 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=a47f3417-1a00-0000-cf29-6a9676140000 pid=5238 execve guuid=95969017-1a00-0000-cf29-6a9677140000 pid=5239 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=95969017-1a00-0000-cf29-6a9677140000 pid=5239 clone guuid=3e2ad917-1a00-0000-cf29-6a9679140000 pid=5241 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=3e2ad917-1a00-0000-cf29-6a9679140000 pid=5241 execve guuid=96593318-1a00-0000-cf29-6a967a140000 pid=5242 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=96593318-1a00-0000-cf29-6a967a140000 pid=5242 execve guuid=deb78b18-1a00-0000-cf29-6a967b140000 pid=5243 /usr/bin/wget net send-data guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=deb78b18-1a00-0000-cf29-6a967b140000 pid=5243 execve guuid=984f3f1b-1a00-0000-cf29-6a967c140000 pid=5244 /usr/bin/curl net send-data write-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=984f3f1b-1a00-0000-cf29-6a967c140000 pid=5244 execve guuid=f559101f-1a00-0000-cf29-6a967d140000 pid=5245 /usr/bin/chmod guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=f559101f-1a00-0000-cf29-6a967d140000 pid=5245 execve guuid=c0755d1f-1a00-0000-cf29-6a967e140000 pid=5246 /usr/bin/bash guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=c0755d1f-1a00-0000-cf29-6a967e140000 pid=5246 clone guuid=ffab9b1f-1a00-0000-cf29-6a9680140000 pid=5248 /usr/bin/rm delete-file guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=ffab9b1f-1a00-0000-cf29-6a9680140000 pid=5248 execve guuid=3739e41f-1a00-0000-cf29-6a9681140000 pid=5249 /usr/bin/rm guuid=78432657-1900-0000-cf29-6a962d140000 pid=5165->guuid=3739e41f-1a00-0000-cf29-6a9681140000 pid=5249 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=f865c557-1900-0000-cf29-6a962e140000 pid=5166->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=9d41a984-1900-0000-cf29-6a962f140000 pid=5167->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=5bce89c1-1900-0000-cf29-6a9632140000 pid=5170 /usr/bin/bash guuid=3e656cc1-1900-0000-cf29-6a9631140000 pid=5169->guuid=5bce89c1-1900-0000-cf29-6a9632140000 pid=5170 clone guuid=796699c2-1900-0000-cf29-6a9635140000 pid=5173->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=7bd835c5-1900-0000-cf29-6a9636140000 pid=5174->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=f66c4dcc-1900-0000-cf29-6a9639140000 pid=5177 /usr/bin/bash guuid=d99c2dcc-1900-0000-cf29-6a9638140000 pid=5176->guuid=f66c4dcc-1900-0000-cf29-6a9639140000 pid=5177 clone guuid=590f3bcd-1900-0000-cf29-6a963c140000 pid=5180->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=cde8cbcf-1900-0000-cf29-6a963d140000 pid=5181->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0ed7c7d3-1900-0000-cf29-6a9640140000 pid=5184 /usr/bin/bash guuid=a1b1afd3-1900-0000-cf29-6a963f140000 pid=5183->guuid=0ed7c7d3-1900-0000-cf29-6a9640140000 pid=5184 clone guuid=fe5094d4-1900-0000-cf29-6a9643140000 pid=5187->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=ca671fd7-1900-0000-cf29-6a9644140000 pid=5188->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=02650bdb-1900-0000-cf29-6a9647140000 pid=5191 /usr/bin/bash guuid=f552edda-1900-0000-cf29-6a9646140000 pid=5190->guuid=02650bdb-1900-0000-cf29-6a9647140000 pid=5191 clone guuid=523accdb-1900-0000-cf29-6a964a140000 pid=5194->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=65844dde-1900-0000-cf29-6a964b140000 pid=5195->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=63d93ee2-1900-0000-cf29-6a964e140000 pid=5198 /usr/bin/bash guuid=56631ee2-1900-0000-cf29-6a964d140000 pid=5197->guuid=63d93ee2-1900-0000-cf29-6a964e140000 pid=5198 clone guuid=64fd0ae3-1900-0000-cf29-6a9651140000 pid=5201->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=45b09de5-1900-0000-cf29-6a9652140000 pid=5202->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=32ed1fed-1900-0000-cf29-6a9655140000 pid=5205 /usr/bin/bash guuid=e152ffec-1900-0000-cf29-6a9654140000 pid=5204->guuid=32ed1fed-1900-0000-cf29-6a9655140000 pid=5205 clone guuid=ded112ee-1900-0000-cf29-6a9658140000 pid=5208->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=0546a8f0-1900-0000-cf29-6a9659140000 pid=5209->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=9567d2f4-1900-0000-cf29-6a965c140000 pid=5212 /usr/bin/bash guuid=3fceb4f4-1900-0000-cf29-6a965b140000 pid=5211->guuid=9567d2f4-1900-0000-cf29-6a965c140000 pid=5212 clone guuid=a62fb7f5-1900-0000-cf29-6a965f140000 pid=5215->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=21af57f8-1900-0000-cf29-6a9660140000 pid=5216->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=d26b08fd-1900-0000-cf29-6a9663140000 pid=5219 /usr/bin/bash guuid=c26be6fc-1900-0000-cf29-6a9662140000 pid=5218->guuid=d26b08fd-1900-0000-cf29-6a9663140000 pid=5219 clone guuid=9f8acdfd-1900-0000-cf29-6a9666140000 pid=5222->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=9da3f900-1a00-0000-cf29-6a9667140000 pid=5223->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=6fe27707-1a00-0000-cf29-6a966a140000 pid=5226 /usr/bin/bash guuid=4a935607-1a00-0000-cf29-6a9669140000 pid=5225->guuid=6fe27707-1a00-0000-cf29-6a966a140000 pid=5226 clone guuid=14374f08-1a00-0000-cf29-6a966d140000 pid=5229->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=4d03fc0a-1a00-0000-cf29-6a966e140000 pid=5230->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=322f800f-1a00-0000-cf29-6a9671140000 pid=5233 /usr/bin/bash guuid=28f24f0f-1a00-0000-cf29-6a9670140000 pid=5232->guuid=322f800f-1a00-0000-cf29-6a9671140000 pid=5233 clone guuid=0a7a7a10-1a00-0000-cf29-6a9674140000 pid=5236->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=0dd25113-1a00-0000-cf29-6a9675140000 pid=5237->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=9cafad17-1a00-0000-cf29-6a9678140000 pid=5240 /usr/bin/bash guuid=95969017-1a00-0000-cf29-6a9677140000 pid=5239->guuid=9cafad17-1a00-0000-cf29-6a9678140000 pid=5240 clone guuid=deb78b18-1a00-0000-cf29-6a967b140000 pid=5243->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=984f3f1b-1a00-0000-cf29-6a967c140000 pid=5244->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=b481781f-1a00-0000-cf29-6a967f140000 pid=5247 /usr/bin/bash guuid=c0755d1f-1a00-0000-cf29-6a967e140000 pid=5246->guuid=b481781f-1a00-0000-cf29-6a967f140000 pid=5247 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh eb2d5d13129b28a8250dfdd4c04001ffc888f7903bbf0a10c155eac8eebbb42c

(this sample)

  
Delivery method
Distributed via web download

Comments