MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f01c461d372f18ac960eb608c92cf7d43175ef5e9d1d4e40f9393ec43208d000. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: f01c461d372f18ac960eb608c92cf7d43175ef5e9d1d4e40f9393ec43208d000
SHA3-384 hash: e27c22d67897adef6fcc788ad1714727f3e2fe93575db08e629dad49330395c6f30860174f9539fd3efcc1f43c2bb271
SHA1 hash: c93997b37c1d95eb0e27b2817b4e9358e8e2e4ad
MD5 hash: 799a835ec301b968a7a26384a01602fe
humanhash: bulldog-timing-lithium-spaghetti
File name:run.sh
Download: download sample
File size:2'907 bytes
First seen:2026-05-24 18:35:02 UTC
Last seen:2026-05-25 07:38:01 UTC
File type: sh
MIME type:text/plain
ssdeep 48:qetcOc2JMI1y1biB8RnRuZUgUgcvyyEV4n4bwLvNRNGd4hHOHhM3I6U:KH2JMuAbiB2RuZ64bwE
TLSH T1215164DB0184EB32D65DC54EB7F4B174610AA18396DF9E09EE842A3D8EC6D4C729DF40
Magika txt
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnaarch64xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxni386xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnloongarch64xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnm68kxnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnmicroblazexnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnmipsxnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnor1kxnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnpowerpcxnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnriscv32xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnriscv64xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnsh2xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnsh4xnxnn/an/aelf ua-wget
http://176.65.139.115/bins/xnxnxnxnxnxnxnxnx86_64xnxnn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
47
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-05-24T15:48:00Z UTC
Last seen:
2026-05-24T17:46:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=6ffa1064-1a00-0000-5ee2-24fb170c0000 pid=3095 /usr/bin/sudo guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100 /tmp/sample.bin guuid=6ffa1064-1a00-0000-5ee2-24fb170c0000 pid=3095->guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100 execve guuid=b6940968-1a00-0000-5ee2-24fb1e0c0000 pid=3102 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=b6940968-1a00-0000-5ee2-24fb1e0c0000 pid=3102 execve guuid=ea391d6d-1a00-0000-5ee2-24fb2a0c0000 pid=3114 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=ea391d6d-1a00-0000-5ee2-24fb2a0c0000 pid=3114 execve guuid=aaf22976-1a00-0000-5ee2-24fb410c0000 pid=3137 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=aaf22976-1a00-0000-5ee2-24fb410c0000 pid=3137 execve guuid=e88a8376-1a00-0000-5ee2-24fb430c0000 pid=3139 /home/sandbox/xnxnxnxnxnxnxnxnaarch64xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=e88a8376-1a00-0000-5ee2-24fb430c0000 pid=3139 execve guuid=2e30cf76-1a00-0000-5ee2-24fb450c0000 pid=3141 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=2e30cf76-1a00-0000-5ee2-24fb450c0000 pid=3141 execve guuid=4f754177-1a00-0000-5ee2-24fb480c0000 pid=3144 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=4f754177-1a00-0000-5ee2-24fb480c0000 pid=3144 execve guuid=9ff08f7a-1a00-0000-5ee2-24fb4f0c0000 pid=3151 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=9ff08f7a-1a00-0000-5ee2-24fb4f0c0000 pid=3151 execve guuid=1cf1e980-1a00-0000-5ee2-24fb5d0c0000 pid=3165 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=1cf1e980-1a00-0000-5ee2-24fb5d0c0000 pid=3165 execve guuid=0d892781-1a00-0000-5ee2-24fb5e0c0000 pid=3166 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=0d892781-1a00-0000-5ee2-24fb5e0c0000 pid=3166 execve guuid=e8fb6981-1a00-0000-5ee2-24fb600c0000 pid=3168 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=e8fb6981-1a00-0000-5ee2-24fb600c0000 pid=3168 execve guuid=2b34b681-1a00-0000-5ee2-24fb620c0000 pid=3170 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=2b34b681-1a00-0000-5ee2-24fb620c0000 pid=3170 execve guuid=e8a33c85-1a00-0000-5ee2-24fb670c0000 pid=3175 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=e8a33c85-1a00-0000-5ee2-24fb670c0000 pid=3175 execve guuid=5e5e428b-1a00-0000-5ee2-24fb750c0000 pid=3189 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=5e5e428b-1a00-0000-5ee2-24fb750c0000 pid=3189 execve guuid=eb06a08b-1a00-0000-5ee2-24fb770c0000 pid=3191 /home/sandbox/xnxnxnxnxnxnxnxnloongarch64xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=eb06a08b-1a00-0000-5ee2-24fb770c0000 pid=3191 execve guuid=4098f78b-1a00-0000-5ee2-24fb780c0000 pid=3192 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=4098f78b-1a00-0000-5ee2-24fb780c0000 pid=3192 execve guuid=0d60628c-1a00-0000-5ee2-24fb7a0c0000 pid=3194 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=0d60628c-1a00-0000-5ee2-24fb7a0c0000 pid=3194 execve guuid=60ff338f-1a00-0000-5ee2-24fb800c0000 pid=3200 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=60ff338f-1a00-0000-5ee2-24fb800c0000 pid=3200 execve guuid=f9a44094-1a00-0000-5ee2-24fb810c0000 pid=3201 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=f9a44094-1a00-0000-5ee2-24fb810c0000 pid=3201 execve guuid=2d939494-1a00-0000-5ee2-24fb820c0000 pid=3202 /home/sandbox/xnxnxnxnxnxnxnxnm68kxnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=2d939494-1a00-0000-5ee2-24fb820c0000 pid=3202 execve guuid=7f44fc94-1a00-0000-5ee2-24fb830c0000 pid=3203 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=7f44fc94-1a00-0000-5ee2-24fb830c0000 pid=3203 execve guuid=ec835e95-1a00-0000-5ee2-24fb840c0000 pid=3204 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=ec835e95-1a00-0000-5ee2-24fb840c0000 pid=3204 execve guuid=733e4c98-1a00-0000-5ee2-24fb850c0000 pid=3205 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=733e4c98-1a00-0000-5ee2-24fb850c0000 pid=3205 execve guuid=0697849d-1a00-0000-5ee2-24fb860c0000 pid=3206 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=0697849d-1a00-0000-5ee2-24fb860c0000 pid=3206 execve guuid=8f46039e-1a00-0000-5ee2-24fb870c0000 pid=3207 /home/sandbox/xnxnxnxnxnxnxnxnmicroblazexnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=8f46039e-1a00-0000-5ee2-24fb870c0000 pid=3207 execve guuid=32f0489e-1a00-0000-5ee2-24fb880c0000 pid=3208 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=32f0489e-1a00-0000-5ee2-24fb880c0000 pid=3208 execve guuid=094c949e-1a00-0000-5ee2-24fb890c0000 pid=3209 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=094c949e-1a00-0000-5ee2-24fb890c0000 pid=3209 execve guuid=12bc61a1-1a00-0000-5ee2-24fb8a0c0000 pid=3210 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=12bc61a1-1a00-0000-5ee2-24fb8a0c0000 pid=3210 execve guuid=1769c3a5-1a00-0000-5ee2-24fb900c0000 pid=3216 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=1769c3a5-1a00-0000-5ee2-24fb900c0000 pid=3216 execve guuid=d54612a6-1a00-0000-5ee2-24fb920c0000 pid=3218 /home/sandbox/xnxnxnxnxnxnxnxnmipsxnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=d54612a6-1a00-0000-5ee2-24fb920c0000 pid=3218 execve guuid=b7c65fa6-1a00-0000-5ee2-24fb940c0000 pid=3220 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=b7c65fa6-1a00-0000-5ee2-24fb940c0000 pid=3220 execve guuid=494c07a7-1a00-0000-5ee2-24fb970c0000 pid=3223 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=494c07a7-1a00-0000-5ee2-24fb970c0000 pid=3223 execve guuid=d7a293ab-1a00-0000-5ee2-24fba00c0000 pid=3232 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=d7a293ab-1a00-0000-5ee2-24fba00c0000 pid=3232 execve guuid=5e6135b1-1a00-0000-5ee2-24fbaa0c0000 pid=3242 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=5e6135b1-1a00-0000-5ee2-24fbaa0c0000 pid=3242 execve guuid=e43196b1-1a00-0000-5ee2-24fbab0c0000 pid=3243 /home/sandbox/xnxnxnxnxnxnxnxnor1kxnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=e43196b1-1a00-0000-5ee2-24fbab0c0000 pid=3243 execve guuid=a0efe2b1-1a00-0000-5ee2-24fbac0c0000 pid=3244 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=a0efe2b1-1a00-0000-5ee2-24fbac0c0000 pid=3244 execve guuid=ab2b38b2-1a00-0000-5ee2-24fbae0c0000 pid=3246 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=ab2b38b2-1a00-0000-5ee2-24fbae0c0000 pid=3246 execve guuid=77bbe0b5-1a00-0000-5ee2-24fbb80c0000 pid=3256 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=77bbe0b5-1a00-0000-5ee2-24fbb80c0000 pid=3256 execve guuid=915296bc-1a00-0000-5ee2-24fbb90c0000 pid=3257 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=915296bc-1a00-0000-5ee2-24fbb90c0000 pid=3257 execve guuid=5645dfbc-1a00-0000-5ee2-24fbba0c0000 pid=3258 /home/sandbox/xnxnxnxnxnxnxnxnpowerpcxnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=5645dfbc-1a00-0000-5ee2-24fbba0c0000 pid=3258 execve guuid=d66520bd-1a00-0000-5ee2-24fbbb0c0000 pid=3259 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=d66520bd-1a00-0000-5ee2-24fbbb0c0000 pid=3259 execve guuid=fa5869bd-1a00-0000-5ee2-24fbbc0c0000 pid=3260 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=fa5869bd-1a00-0000-5ee2-24fbbc0c0000 pid=3260 execve guuid=51ac33c1-1a00-0000-5ee2-24fbbd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=51ac33c1-1a00-0000-5ee2-24fbbd0c0000 pid=3261 execve guuid=7d2d52c5-1a00-0000-5ee2-24fbbe0c0000 pid=3262 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=7d2d52c5-1a00-0000-5ee2-24fbbe0c0000 pid=3262 execve guuid=49c7acc5-1a00-0000-5ee2-24fbbf0c0000 pid=3263 /home/sandbox/xnxnxnxnxnxnxnxnriscv32xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=49c7acc5-1a00-0000-5ee2-24fbbf0c0000 pid=3263 execve guuid=e26bf4c5-1a00-0000-5ee2-24fbc00c0000 pid=3264 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=e26bf4c5-1a00-0000-5ee2-24fbc00c0000 pid=3264 execve guuid=381b5ac6-1a00-0000-5ee2-24fbc10c0000 pid=3265 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=381b5ac6-1a00-0000-5ee2-24fbc10c0000 pid=3265 execve guuid=c659efc9-1a00-0000-5ee2-24fbc50c0000 pid=3269 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=c659efc9-1a00-0000-5ee2-24fbc50c0000 pid=3269 execve guuid=7e19c6cd-1a00-0000-5ee2-24fbcd0c0000 pid=3277 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=7e19c6cd-1a00-0000-5ee2-24fbcd0c0000 pid=3277 execve guuid=710309ce-1a00-0000-5ee2-24fbcf0c0000 pid=3279 /home/sandbox/xnxnxnxnxnxnxnxnriscv64xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=710309ce-1a00-0000-5ee2-24fbcf0c0000 pid=3279 execve guuid=57d043ce-1a00-0000-5ee2-24fbd00c0000 pid=3280 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=57d043ce-1a00-0000-5ee2-24fbd00c0000 pid=3280 execve guuid=197299ce-1a00-0000-5ee2-24fbd20c0000 pid=3282 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=197299ce-1a00-0000-5ee2-24fbd20c0000 pid=3282 execve guuid=6e0e98d2-1a00-0000-5ee2-24fbd60c0000 pid=3286 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=6e0e98d2-1a00-0000-5ee2-24fbd60c0000 pid=3286 execve guuid=e9ffedd8-1a00-0000-5ee2-24fbdd0c0000 pid=3293 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=e9ffedd8-1a00-0000-5ee2-24fbdd0c0000 pid=3293 execve guuid=02f867d9-1a00-0000-5ee2-24fbde0c0000 pid=3294 /home/sandbox/xnxnxnxnxnxnxnxnsh2xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=02f867d9-1a00-0000-5ee2-24fbde0c0000 pid=3294 execve guuid=6147ded9-1a00-0000-5ee2-24fbdf0c0000 pid=3295 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=6147ded9-1a00-0000-5ee2-24fbdf0c0000 pid=3295 execve guuid=0d4e7dda-1a00-0000-5ee2-24fbe00c0000 pid=3296 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=0d4e7dda-1a00-0000-5ee2-24fbe00c0000 pid=3296 execve guuid=725f3ade-1a00-0000-5ee2-24fbe50c0000 pid=3301 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=725f3ade-1a00-0000-5ee2-24fbe50c0000 pid=3301 execve guuid=ee2d20e5-1a00-0000-5ee2-24fbf40c0000 pid=3316 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=ee2d20e5-1a00-0000-5ee2-24fbf40c0000 pid=3316 execve guuid=ac4b5ce5-1a00-0000-5ee2-24fbf60c0000 pid=3318 /home/sandbox/xnxnxnxnxnxnxnxnsh4xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=ac4b5ce5-1a00-0000-5ee2-24fbf60c0000 pid=3318 execve guuid=83fd90e5-1a00-0000-5ee2-24fbf80c0000 pid=3320 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=83fd90e5-1a00-0000-5ee2-24fbf80c0000 pid=3320 execve guuid=5b81d3e5-1a00-0000-5ee2-24fbfa0c0000 pid=3322 /usr/bin/wget net send-data guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=5b81d3e5-1a00-0000-5ee2-24fbfa0c0000 pid=3322 execve guuid=8fb6d4e8-1a00-0000-5ee2-24fbfb0c0000 pid=3323 /usr/bin/curl net send-data write-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=8fb6d4e8-1a00-0000-5ee2-24fbfb0c0000 pid=3323 execve guuid=b89368ee-1a00-0000-5ee2-24fb020d0000 pid=3330 /usr/bin/chmod guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=b89368ee-1a00-0000-5ee2-24fb020d0000 pid=3330 execve guuid=c5dfb2ee-1a00-0000-5ee2-24fb040d0000 pid=3332 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=c5dfb2ee-1a00-0000-5ee2-24fb040d0000 pid=3332 execve guuid=ba88f7ee-1a00-0000-5ee2-24fb060d0000 pid=3334 /usr/bin/rm delete-file guuid=3c587b67-1a00-0000-5ee2-24fb1c0c0000 pid=3100->guuid=ba88f7ee-1a00-0000-5ee2-24fb060d0000 pid=3334 execve 38fcf1c2-9535-5d52-a9e6-3b00441a8433 176.65.139.115:80 guuid=b6940968-1a00-0000-5ee2-24fb1e0c0000 pid=3102->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 161B guuid=ea391d6d-1a00-0000-5ee2-24fb2a0c0000 pid=3114->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 110B guuid=4f754177-1a00-0000-5ee2-24fb480c0000 pid=3144->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 158B guuid=9ff08f7a-1a00-0000-5ee2-24fb4f0c0000 pid=3151->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 107B guuid=2b34b681-1a00-0000-5ee2-24fb620c0000 pid=3170->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 165B guuid=e8a33c85-1a00-0000-5ee2-24fb670c0000 pid=3175->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 114B guuid=0d60628c-1a00-0000-5ee2-24fb7a0c0000 pid=3194->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 158B guuid=60ff338f-1a00-0000-5ee2-24fb800c0000 pid=3200->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 107B guuid=ec835e95-1a00-0000-5ee2-24fb840c0000 pid=3204->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 164B guuid=733e4c98-1a00-0000-5ee2-24fb850c0000 pid=3205->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 113B guuid=094c949e-1a00-0000-5ee2-24fb890c0000 pid=3209->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 158B guuid=12bc61a1-1a00-0000-5ee2-24fb8a0c0000 pid=3210->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 107B guuid=494c07a7-1a00-0000-5ee2-24fb970c0000 pid=3223->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 158B guuid=d7a293ab-1a00-0000-5ee2-24fba00c0000 pid=3232->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 107B guuid=ab2b38b2-1a00-0000-5ee2-24fbae0c0000 pid=3246->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 161B guuid=77bbe0b5-1a00-0000-5ee2-24fbb80c0000 pid=3256->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 110B guuid=fa5869bd-1a00-0000-5ee2-24fbbc0c0000 pid=3260->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 161B guuid=51ac33c1-1a00-0000-5ee2-24fbbd0c0000 pid=3261->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 110B guuid=381b5ac6-1a00-0000-5ee2-24fbc10c0000 pid=3265->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 161B guuid=c659efc9-1a00-0000-5ee2-24fbc50c0000 pid=3269->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 110B guuid=197299ce-1a00-0000-5ee2-24fbd20c0000 pid=3282->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 157B guuid=6e0e98d2-1a00-0000-5ee2-24fbd60c0000 pid=3286->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 106B guuid=0d4e7dda-1a00-0000-5ee2-24fbe00c0000 pid=3296->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 157B guuid=725f3ade-1a00-0000-5ee2-24fbe50c0000 pid=3301->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 106B guuid=5b81d3e5-1a00-0000-5ee2-24fbfa0c0000 pid=3322->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 160B guuid=8fb6d4e8-1a00-0000-5ee2-24fbfb0c0000 pid=3323->38fcf1c2-9535-5d52-a9e6-3b00441a8433 send: 109B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-05-24 18:34:24 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f01c461d372f18ac960eb608c92cf7d43175ef5e9d1d4e40f9393ec43208d000

(this sample)

  
Delivery method
Distributed via web download

Comments