MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef42b30b9b8eb300a1ea698fe205f494a9017ddf07ee984aad6763db9ce64c83. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: ef42b30b9b8eb300a1ea698fe205f494a9017ddf07ee984aad6763db9ce64c83
SHA3-384 hash: 7f2beff7178d77bbe4d4a6c109ed1242fcc80462c6593f7d07a66c3652d1b59505859ba6dc3419a3960d152bbd87d644
SHA1 hash: a87d6e59e9c9c5040928e84901f5316e8a3d8cb6
MD5 hash: 8f1b9bb908c69b5ecc6498f69e5cf54a
humanhash: princess-colorado-delaware-sink
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-03 20:29:48 UTC
Last seen:2026-06-04 08:32:51 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZoha0zkcE46aO3corv17:e9Qp+Ms07qaOMgv17
TLSH T1D801CECFC112D7104095E8AE62A761907412C7CB26864BB8BF9C483DDBBD75C7125F98
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/uA5Bn/an/aelf ua-wget
http://188.132.232.81/mSDn/an/aelf ua-wget
http://188.132.232.81/bzqn/an/aelf ua-wget
http://188.132.232.81/sKW8n/an/aelf ua-wget
http://188.132.232.81/wZedn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-03T17:36:00Z UTC
Last seen:
2026-06-04T00:30:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=084e0dbd-1600-0000-8b01-75099e0c0000 pid=3230 /usr/bin/sudo guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233 /tmp/sample.bin write-file guuid=084e0dbd-1600-0000-8b01-75099e0c0000 pid=3230->guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233 execve guuid=93df7bbf-1600-0000-8b01-7509a20c0000 pid=3234 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=93df7bbf-1600-0000-8b01-7509a20c0000 pid=3234 execve guuid=b1b1debf-1600-0000-8b01-7509a40c0000 pid=3236 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=b1b1debf-1600-0000-8b01-7509a40c0000 pid=3236 execve guuid=97825cc0-1600-0000-8b01-7509a70c0000 pid=3239 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=97825cc0-1600-0000-8b01-7509a70c0000 pid=3239 execve guuid=4defbfc0-1600-0000-8b01-7509a90c0000 pid=3241 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=4defbfc0-1600-0000-8b01-7509a90c0000 pid=3241 execve guuid=d7a42bc1-1600-0000-8b01-7509ab0c0000 pid=3243 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=d7a42bc1-1600-0000-8b01-7509ab0c0000 pid=3243 execve guuid=7950c7c1-1600-0000-8b01-7509ac0c0000 pid=3244 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=7950c7c1-1600-0000-8b01-7509ac0c0000 pid=3244 execve guuid=332641c2-1600-0000-8b01-7509ad0c0000 pid=3245 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=332641c2-1600-0000-8b01-7509ad0c0000 pid=3245 execve guuid=3b82a6c2-1600-0000-8b01-7509af0c0000 pid=3247 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=3b82a6c2-1600-0000-8b01-7509af0c0000 pid=3247 execve guuid=2034fcc2-1600-0000-8b01-7509b10c0000 pid=3249 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2034fcc2-1600-0000-8b01-7509b10c0000 pid=3249 execve guuid=cde856c3-1600-0000-8b01-7509b40c0000 pid=3252 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=cde856c3-1600-0000-8b01-7509b40c0000 pid=3252 execve guuid=9989b3c3-1600-0000-8b01-7509b60c0000 pid=3254 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=9989b3c3-1600-0000-8b01-7509b60c0000 pid=3254 execve guuid=126f0ec4-1600-0000-8b01-7509b80c0000 pid=3256 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=126f0ec4-1600-0000-8b01-7509b80c0000 pid=3256 execve guuid=db657ac4-1600-0000-8b01-7509ba0c0000 pid=3258 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=db657ac4-1600-0000-8b01-7509ba0c0000 pid=3258 execve guuid=e756edc4-1600-0000-8b01-7509bb0c0000 pid=3259 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=e756edc4-1600-0000-8b01-7509bb0c0000 pid=3259 execve guuid=f15166c5-1600-0000-8b01-7509bc0c0000 pid=3260 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=f15166c5-1600-0000-8b01-7509bc0c0000 pid=3260 execve guuid=1d63dac5-1600-0000-8b01-7509bd0c0000 pid=3261 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=1d63dac5-1600-0000-8b01-7509bd0c0000 pid=3261 execve guuid=502d42c6-1600-0000-8b01-7509c00c0000 pid=3264 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=502d42c6-1600-0000-8b01-7509c00c0000 pid=3264 execve guuid=e8bba7c6-1600-0000-8b01-7509c20c0000 pid=3266 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=e8bba7c6-1600-0000-8b01-7509c20c0000 pid=3266 execve guuid=823109c7-1600-0000-8b01-7509c50c0000 pid=3269 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=823109c7-1600-0000-8b01-7509c50c0000 pid=3269 execve guuid=590715c8-1600-0000-8b01-7509c70c0000 pid=3271 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=590715c8-1600-0000-8b01-7509c70c0000 pid=3271 execve guuid=6d82e4c8-1600-0000-8b01-7509c80c0000 pid=3272 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=6d82e4c8-1600-0000-8b01-7509c80c0000 pid=3272 execve guuid=bdef94c9-1600-0000-8b01-7509c90c0000 pid=3273 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=bdef94c9-1600-0000-8b01-7509c90c0000 pid=3273 execve guuid=c86c37ca-1600-0000-8b01-7509ca0c0000 pid=3274 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=c86c37ca-1600-0000-8b01-7509ca0c0000 pid=3274 execve guuid=1edcc6ca-1600-0000-8b01-7509cb0c0000 pid=3275 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=1edcc6ca-1600-0000-8b01-7509cb0c0000 pid=3275 execve guuid=081457cb-1600-0000-8b01-7509cc0c0000 pid=3276 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=081457cb-1600-0000-8b01-7509cc0c0000 pid=3276 execve guuid=4c65d7cb-1600-0000-8b01-7509cd0c0000 pid=3277 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=4c65d7cb-1600-0000-8b01-7509cd0c0000 pid=3277 execve guuid=a6ea4fcc-1600-0000-8b01-7509ce0c0000 pid=3278 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=a6ea4fcc-1600-0000-8b01-7509ce0c0000 pid=3278 execve guuid=036dc1cc-1600-0000-8b01-7509d00c0000 pid=3280 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=036dc1cc-1600-0000-8b01-7509d00c0000 pid=3280 execve guuid=6b1a39cd-1600-0000-8b01-7509d10c0000 pid=3281 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=6b1a39cd-1600-0000-8b01-7509d10c0000 pid=3281 execve guuid=be24b6cd-1600-0000-8b01-7509d20c0000 pid=3282 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=be24b6cd-1600-0000-8b01-7509d20c0000 pid=3282 execve guuid=0b562ece-1600-0000-8b01-7509d40c0000 pid=3284 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=0b562ece-1600-0000-8b01-7509d40c0000 pid=3284 execve guuid=73148ece-1600-0000-8b01-7509d60c0000 pid=3286 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=73148ece-1600-0000-8b01-7509d60c0000 pid=3286 execve guuid=6751ecce-1600-0000-8b01-7509d80c0000 pid=3288 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=6751ecce-1600-0000-8b01-7509d80c0000 pid=3288 execve guuid=f77650cf-1600-0000-8b01-7509db0c0000 pid=3291 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=f77650cf-1600-0000-8b01-7509db0c0000 pid=3291 execve guuid=6b8eaccf-1600-0000-8b01-7509dd0c0000 pid=3293 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=6b8eaccf-1600-0000-8b01-7509dd0c0000 pid=3293 execve guuid=a6980ed0-1600-0000-8b01-7509e00c0000 pid=3296 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=a6980ed0-1600-0000-8b01-7509e00c0000 pid=3296 execve guuid=1ac273d0-1600-0000-8b01-7509e20c0000 pid=3298 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=1ac273d0-1600-0000-8b01-7509e20c0000 pid=3298 execve guuid=0b2fd6d0-1600-0000-8b01-7509e50c0000 pid=3301 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=0b2fd6d0-1600-0000-8b01-7509e50c0000 pid=3301 execve guuid=968131d1-1600-0000-8b01-7509e70c0000 pid=3303 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=968131d1-1600-0000-8b01-7509e70c0000 pid=3303 execve guuid=3f0a90d1-1600-0000-8b01-7509e90c0000 pid=3305 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=3f0a90d1-1600-0000-8b01-7509e90c0000 pid=3305 execve guuid=65d5e7d1-1600-0000-8b01-7509ec0c0000 pid=3308 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=65d5e7d1-1600-0000-8b01-7509ec0c0000 pid=3308 execve guuid=0baa43d2-1600-0000-8b01-7509ee0c0000 pid=3310 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=0baa43d2-1600-0000-8b01-7509ee0c0000 pid=3310 execve guuid=79e997d2-1600-0000-8b01-7509f00c0000 pid=3312 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=79e997d2-1600-0000-8b01-7509f00c0000 pid=3312 execve guuid=7fcafdd2-1600-0000-8b01-7509f20c0000 pid=3314 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=7fcafdd2-1600-0000-8b01-7509f20c0000 pid=3314 execve guuid=82a666d3-1600-0000-8b01-7509f30c0000 pid=3315 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=82a666d3-1600-0000-8b01-7509f30c0000 pid=3315 execve guuid=0efbcbd3-1600-0000-8b01-7509f50c0000 pid=3317 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=0efbcbd3-1600-0000-8b01-7509f50c0000 pid=3317 execve guuid=30b437d4-1600-0000-8b01-7509f60c0000 pid=3318 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=30b437d4-1600-0000-8b01-7509f60c0000 pid=3318 execve guuid=8f47a9d4-1600-0000-8b01-7509f70c0000 pid=3319 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=8f47a9d4-1600-0000-8b01-7509f70c0000 pid=3319 execve guuid=2b6b19d5-1600-0000-8b01-7509f90c0000 pid=3321 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2b6b19d5-1600-0000-8b01-7509f90c0000 pid=3321 execve guuid=8d3d6ad5-1600-0000-8b01-7509fb0c0000 pid=3323 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=8d3d6ad5-1600-0000-8b01-7509fb0c0000 pid=3323 execve guuid=19dab3d5-1600-0000-8b01-7509fd0c0000 pid=3325 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=19dab3d5-1600-0000-8b01-7509fd0c0000 pid=3325 execve guuid=6f890cd6-1600-0000-8b01-7509000d0000 pid=3328 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=6f890cd6-1600-0000-8b01-7509000d0000 pid=3328 execve guuid=939364d6-1600-0000-8b01-7509020d0000 pid=3330 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=939364d6-1600-0000-8b01-7509020d0000 pid=3330 execve guuid=2cf7bcd6-1600-0000-8b01-7509050d0000 pid=3333 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2cf7bcd6-1600-0000-8b01-7509050d0000 pid=3333 execve guuid=aee61fd7-1600-0000-8b01-7509070d0000 pid=3335 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=aee61fd7-1600-0000-8b01-7509070d0000 pid=3335 execve guuid=e16589d7-1600-0000-8b01-75090a0d0000 pid=3338 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=e16589d7-1600-0000-8b01-75090a0d0000 pid=3338 execve guuid=9a9cf5d7-1600-0000-8b01-75090c0d0000 pid=3340 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=9a9cf5d7-1600-0000-8b01-75090c0d0000 pid=3340 execve guuid=866454d8-1600-0000-8b01-75090f0d0000 pid=3343 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=866454d8-1600-0000-8b01-75090f0d0000 pid=3343 execve guuid=1ef8b5d8-1600-0000-8b01-7509110d0000 pid=3345 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=1ef8b5d8-1600-0000-8b01-7509110d0000 pid=3345 execve guuid=1d5317d9-1600-0000-8b01-7509140d0000 pid=3348 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=1d5317d9-1600-0000-8b01-7509140d0000 pid=3348 execve guuid=54817cd9-1600-0000-8b01-7509160d0000 pid=3350 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=54817cd9-1600-0000-8b01-7509160d0000 pid=3350 execve guuid=5f25e7d9-1600-0000-8b01-7509180d0000 pid=3352 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=5f25e7d9-1600-0000-8b01-7509180d0000 pid=3352 execve guuid=772967da-1600-0000-8b01-7509190d0000 pid=3353 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=772967da-1600-0000-8b01-7509190d0000 pid=3353 execve guuid=7569f1da-1600-0000-8b01-75091a0d0000 pid=3354 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=7569f1da-1600-0000-8b01-75091a0d0000 pid=3354 execve guuid=24f96adb-1600-0000-8b01-75091c0d0000 pid=3356 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=24f96adb-1600-0000-8b01-75091c0d0000 pid=3356 execve guuid=1145c6db-1600-0000-8b01-75091e0d0000 pid=3358 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=1145c6db-1600-0000-8b01-75091e0d0000 pid=3358 execve guuid=511c19dc-1600-0000-8b01-7509200d0000 pid=3360 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=511c19dc-1600-0000-8b01-7509200d0000 pid=3360 execve guuid=f3b26cdc-1600-0000-8b01-7509230d0000 pid=3363 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=f3b26cdc-1600-0000-8b01-7509230d0000 pid=3363 execve guuid=bea6c3dc-1600-0000-8b01-7509250d0000 pid=3365 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=bea6c3dc-1600-0000-8b01-7509250d0000 pid=3365 execve guuid=62471bdd-1600-0000-8b01-7509270d0000 pid=3367 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=62471bdd-1600-0000-8b01-7509270d0000 pid=3367 execve guuid=da1e81dd-1600-0000-8b01-7509280d0000 pid=3368 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=da1e81dd-1600-0000-8b01-7509280d0000 pid=3368 execve guuid=ad80e3dd-1600-0000-8b01-75092b0d0000 pid=3371 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=ad80e3dd-1600-0000-8b01-75092b0d0000 pid=3371 execve guuid=86963ade-1600-0000-8b01-75092d0d0000 pid=3373 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=86963ade-1600-0000-8b01-75092d0d0000 pid=3373 execve guuid=a33e94de-1600-0000-8b01-7509300d0000 pid=3376 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=a33e94de-1600-0000-8b01-7509300d0000 pid=3376 execve guuid=17e1ecde-1600-0000-8b01-7509320d0000 pid=3378 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=17e1ecde-1600-0000-8b01-7509320d0000 pid=3378 execve guuid=5a0f49df-1600-0000-8b01-7509350d0000 pid=3381 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=5a0f49df-1600-0000-8b01-7509350d0000 pid=3381 execve guuid=04fac2df-1600-0000-8b01-7509380d0000 pid=3384 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=04fac2df-1600-0000-8b01-7509380d0000 pid=3384 execve guuid=c70520e0-1600-0000-8b01-75093a0d0000 pid=3386 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=c70520e0-1600-0000-8b01-75093a0d0000 pid=3386 execve guuid=e92b7be0-1600-0000-8b01-75093c0d0000 pid=3388 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=e92b7be0-1600-0000-8b01-75093c0d0000 pid=3388 execve guuid=0428dae0-1600-0000-8b01-75093e0d0000 pid=3390 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=0428dae0-1600-0000-8b01-75093e0d0000 pid=3390 execve guuid=f9ab3fe1-1600-0000-8b01-7509410d0000 pid=3393 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=f9ab3fe1-1600-0000-8b01-7509410d0000 pid=3393 execve guuid=c6959be1-1600-0000-8b01-7509430d0000 pid=3395 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=c6959be1-1600-0000-8b01-7509430d0000 pid=3395 execve guuid=fe96fde1-1600-0000-8b01-7509450d0000 pid=3397 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=fe96fde1-1600-0000-8b01-7509450d0000 pid=3397 execve guuid=422054e2-1600-0000-8b01-7509470d0000 pid=3399 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=422054e2-1600-0000-8b01-7509470d0000 pid=3399 execve guuid=d4a0a8e2-1600-0000-8b01-7509490d0000 pid=3401 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=d4a0a8e2-1600-0000-8b01-7509490d0000 pid=3401 execve guuid=af520ae3-1600-0000-8b01-75094a0d0000 pid=3402 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=af520ae3-1600-0000-8b01-75094a0d0000 pid=3402 execve guuid=ec6071e3-1600-0000-8b01-75094b0d0000 pid=3403 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=ec6071e3-1600-0000-8b01-75094b0d0000 pid=3403 execve guuid=adbacde3-1600-0000-8b01-75094d0d0000 pid=3405 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=adbacde3-1600-0000-8b01-75094d0d0000 pid=3405 execve guuid=e16a2be4-1600-0000-8b01-7509500d0000 pid=3408 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=e16a2be4-1600-0000-8b01-7509500d0000 pid=3408 execve guuid=16ff82e4-1600-0000-8b01-7509520d0000 pid=3410 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=16ff82e4-1600-0000-8b01-7509520d0000 pid=3410 execve guuid=284cdde4-1600-0000-8b01-7509540d0000 pid=3412 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=284cdde4-1600-0000-8b01-7509540d0000 pid=3412 execve guuid=fce136e5-1600-0000-8b01-7509560d0000 pid=3414 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=fce136e5-1600-0000-8b01-7509560d0000 pid=3414 execve guuid=9527bae5-1600-0000-8b01-7509570d0000 pid=3415 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=9527bae5-1600-0000-8b01-7509570d0000 pid=3415 execve guuid=61ad44e6-1600-0000-8b01-7509580d0000 pid=3416 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=61ad44e6-1600-0000-8b01-7509580d0000 pid=3416 execve guuid=2d8cc5e6-1600-0000-8b01-7509590d0000 pid=3417 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2d8cc5e6-1600-0000-8b01-7509590d0000 pid=3417 execve guuid=331d48e7-1600-0000-8b01-75095a0d0000 pid=3418 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=331d48e7-1600-0000-8b01-75095a0d0000 pid=3418 execve guuid=5292c8e7-1600-0000-8b01-75095b0d0000 pid=3419 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=5292c8e7-1600-0000-8b01-75095b0d0000 pid=3419 execve guuid=96c64be8-1600-0000-8b01-75095c0d0000 pid=3420 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=96c64be8-1600-0000-8b01-75095c0d0000 pid=3420 execve guuid=3302c9e8-1600-0000-8b01-75095d0d0000 pid=3421 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=3302c9e8-1600-0000-8b01-75095d0d0000 pid=3421 execve guuid=d3c04fe9-1600-0000-8b01-75095e0d0000 pid=3422 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=d3c04fe9-1600-0000-8b01-75095e0d0000 pid=3422 execve guuid=e1e6c9e9-1600-0000-8b01-75095f0d0000 pid=3423 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=e1e6c9e9-1600-0000-8b01-75095f0d0000 pid=3423 execve guuid=d15145ea-1600-0000-8b01-7509600d0000 pid=3424 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=d15145ea-1600-0000-8b01-7509600d0000 pid=3424 execve guuid=c83abcea-1600-0000-8b01-7509610d0000 pid=3425 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=c83abcea-1600-0000-8b01-7509610d0000 pid=3425 execve guuid=2e7436eb-1600-0000-8b01-7509620d0000 pid=3426 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2e7436eb-1600-0000-8b01-7509620d0000 pid=3426 execve guuid=f706a3eb-1600-0000-8b01-7509630d0000 pid=3427 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=f706a3eb-1600-0000-8b01-7509630d0000 pid=3427 execve guuid=fab81cec-1600-0000-8b01-7509640d0000 pid=3428 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=fab81cec-1600-0000-8b01-7509640d0000 pid=3428 execve guuid=5ffe89ec-1600-0000-8b01-7509650d0000 pid=3429 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=5ffe89ec-1600-0000-8b01-7509650d0000 pid=3429 execve guuid=2ce4fdec-1600-0000-8b01-7509660d0000 pid=3430 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2ce4fdec-1600-0000-8b01-7509660d0000 pid=3430 execve guuid=995e72ed-1600-0000-8b01-7509670d0000 pid=3431 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=995e72ed-1600-0000-8b01-7509670d0000 pid=3431 execve guuid=aaf7eaed-1600-0000-8b01-7509680d0000 pid=3432 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=aaf7eaed-1600-0000-8b01-7509680d0000 pid=3432 execve guuid=2f676dee-1600-0000-8b01-75096a0d0000 pid=3434 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2f676dee-1600-0000-8b01-75096a0d0000 pid=3434 execve guuid=8c98f5ee-1600-0000-8b01-75096b0d0000 pid=3435 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=8c98f5ee-1600-0000-8b01-75096b0d0000 pid=3435 execve guuid=a7596aef-1600-0000-8b01-75096c0d0000 pid=3436 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=a7596aef-1600-0000-8b01-75096c0d0000 pid=3436 execve guuid=2ddccaef-1600-0000-8b01-75096e0d0000 pid=3438 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=2ddccaef-1600-0000-8b01-75096e0d0000 pid=3438 execve guuid=784d30f0-1600-0000-8b01-7509710d0000 pid=3441 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=784d30f0-1600-0000-8b01-7509710d0000 pid=3441 execve guuid=d8aefdf0-1600-0000-8b01-7509740d0000 pid=3444 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=d8aefdf0-1600-0000-8b01-7509740d0000 pid=3444 execve guuid=02f461f1-1600-0000-8b01-7509770d0000 pid=3447 /usr/bin/ls guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=02f461f1-1600-0000-8b01-7509770d0000 pid=3447 execve guuid=b517c4f1-1600-0000-8b01-7509790d0000 pid=3449 /usr/bin/rm guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=b517c4f1-1600-0000-8b01-7509790d0000 pid=3449 execve guuid=d551fbf1-1600-0000-8b01-75097b0d0000 pid=3451 /usr/bin/wget net send-data write-file guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=d551fbf1-1600-0000-8b01-75097b0d0000 pid=3451 execve guuid=64860437-1700-0000-8b01-75090e0e0000 pid=3598 /usr/bin/chmod guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=64860437-1700-0000-8b01-75090e0e0000 pid=3598 execve guuid=62d37b37-1700-0000-8b01-7509100e0000 pid=3600 /tmp/uA5B guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=62d37b37-1700-0000-8b01-7509100e0000 pid=3600 execve guuid=56d89938-1700-0000-8b01-7509140e0000 pid=3604 /usr/bin/rm guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=56d89938-1700-0000-8b01-7509140e0000 pid=3604 execve guuid=ca90e638-1700-0000-8b01-7509170e0000 pid=3607 /usr/bin/wget net send-data write-file guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=ca90e638-1700-0000-8b01-7509170e0000 pid=3607 execve guuid=adb71e7d-1700-0000-8b01-7509870e0000 pid=3719 /usr/bin/chmod guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=adb71e7d-1700-0000-8b01-7509870e0000 pid=3719 execve guuid=3e2f637d-1700-0000-8b01-7509890e0000 pid=3721 /tmp/mSD guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=3e2f637d-1700-0000-8b01-7509890e0000 pid=3721 execve guuid=9742157e-1700-0000-8b01-75098c0e0000 pid=3724 /usr/bin/rm guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=9742157e-1700-0000-8b01-75098c0e0000 pid=3724 execve guuid=18ac547e-1700-0000-8b01-75098d0e0000 pid=3725 /usr/bin/wget net send-data write-file guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=18ac547e-1700-0000-8b01-75098d0e0000 pid=3725 execve guuid=57967bd1-1700-0000-8b01-7509690f0000 pid=3945 /usr/bin/chmod guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=57967bd1-1700-0000-8b01-7509690f0000 pid=3945 execve guuid=0783f3d1-1700-0000-8b01-75096b0f0000 pid=3947 /tmp/bzq guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=0783f3d1-1700-0000-8b01-75096b0f0000 pid=3947 execve guuid=af3fe5d2-1700-0000-8b01-7509700f0000 pid=3952 /usr/bin/rm guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=af3fe5d2-1700-0000-8b01-7509700f0000 pid=3952 execve guuid=7f2ec7d3-1700-0000-8b01-7509730f0000 pid=3955 /usr/bin/wget net send-data write-file guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=7f2ec7d3-1700-0000-8b01-7509730f0000 pid=3955 execve guuid=aa21d017-1800-0000-8b01-75091e100000 pid=4126 /usr/bin/chmod guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=aa21d017-1800-0000-8b01-75091e100000 pid=4126 execve guuid=39b12318-1800-0000-8b01-750921100000 pid=4129 /tmp/sKW8 guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=39b12318-1800-0000-8b01-750921100000 pid=4129 execve guuid=4793ed18-1800-0000-8b01-750926100000 pid=4134 /usr/bin/rm guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=4793ed18-1800-0000-8b01-750926100000 pid=4134 execve guuid=8fbf3d19-1800-0000-8b01-750928100000 pid=4136 /usr/bin/wget net send-data write-file guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=8fbf3d19-1800-0000-8b01-750928100000 pid=4136 execve guuid=fc81c01f-1800-0000-8b01-750947100000 pid=4167 /usr/bin/chmod guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=fc81c01f-1800-0000-8b01-750947100000 pid=4167 execve guuid=9ac81920-1800-0000-8b01-750949100000 pid=4169 /tmp/wZed guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=9ac81920-1800-0000-8b01-750949100000 pid=4169 execve guuid=6a911022-1800-0000-8b01-750950100000 pid=4176 /usr/bin/rm delete-file guuid=1e2d3fbf-1600-0000-8b01-7509a10c0000 pid=3233->guuid=6a911022-1800-0000-8b01-750950100000 pid=4176 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=d551fbf1-1600-0000-8b01-75097b0d0000 pid=3451->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=ca90e638-1700-0000-8b01-7509170e0000 pid=3607->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=18ac547e-1700-0000-8b01-75098d0e0000 pid=3725->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=7f2ec7d3-1700-0000-8b01-7509730f0000 pid=3955->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=8fbf3d19-1800-0000-8b01-750928100000 pid=4136->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-03 20:30:57 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ef42b30b9b8eb300a1ea698fe205f494a9017ddf07ee984aad6763db9ce64c83

(this sample)

  
Delivery method
Distributed via web download

Comments