MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f778e9f251fa6fa4fabdef19a275b16fa4576706f429f6308abce8a8a2fed126. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ladvix


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f778e9f251fa6fa4fabdef19a275b16fa4576706f429f6308abce8a8a2fed126
SHA3-384 hash: 4d7ececed3c386366b72621dc15b93d6941f1e46f720010f4ed35e2ac979ed0d0a6b7758a2ab63da12942ef80bfe6b8e
SHA1 hash: 3547efffd6ddc06ea59a4580083a8fa08743f393
MD5 hash: 9d183242ee6050eb7f2d12699a736495
humanhash: white-red-michigan-texas
File name:run.sh
Download: download sample
Signature Ladvix
File size:2'881 bytes
First seen:2026-05-05 14:11:08 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:T82JMvZbiBvquZuEXEnE2EhEalPbwm3JUfinhM3G:T82JMvZbiBvquZuucvy/Pbw2nhM3G
TLSH T131510EAB02158B35D60D864FF7F47174711BA9D6FADBCA04ED48082D4FD9D8C7295E80
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnaarch64xnxn933168973ff9e26e354cc9bdb4cb37b7ec4ef81947290b89bfc30a8929d2f56a Ladvixladvix
http://193.32.208.35/bins/xnxnxnxnxnxnxnxni386xnxn423a13213e9e37300727c154bdec1a5d3f240c83ca3695b962365108a1d0097f Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnloongarch64xnxn1e3e9b2ad36356ce5b7f1fcf4abb66d0cff37fda021a90ad2af41a2bb5275741 Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnm68kxnxn40c93abec87e436c68d609f7a558d2a898a7ba49e9282de1cbdb331a5e81a4fa Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnmicroblazexnxne661e40c6814edda59dfca1061d1440d22ab685430ae8e75bb58978b313542fd Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnmipsxnxn47b351de3cfef8df5820a2c9d968a2864679195f1fdffa34c7ee54da7735ba8f Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnor1kxnxnbe849468b15f8987d74819a3caa088404f22f05a0b9b2f8f9845168b6b45e87c Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnpowerpcxnxn5976da135be2ac5be7afce28f0f1ae50ce488dfc532a8c5db462a777c5ba8e81 Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnriscv32xnxn1424188500d83476b60306fb61fb54b3eb6b090cace33baced826073c5f2d402 Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnriscv64xnxn913b687d0f4253c9200c2aca376de224c84d630d290e8c722f371d3b5ebb7fe7 Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnsh2xnxn710bc2f818d126bd6a6e809d1bc493b634134fcbd4fe35ea2f8d3e5674766377 Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnsh4xnxn7d1378ea5bf78e4a471779664df21232142400d1567aae516010d2a6f19113a0 Miraimirai
http://193.32.208.35/bins/xnxnxnxnxnxnxnxnx86_64xnxnf61639155c40e20acc672bd3b982757af46e833a62e670852b93ac93698a3699 Ladvixladvix

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-05-04T22:27:00Z UTC
Last seen:
2026-05-05T13:43:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=64b2b518-2100-0000-7418-8630f10c0000 pid=3313 /usr/bin/sudo guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320 /tmp/sample.bin guuid=64b2b518-2100-0000-7418-8630f10c0000 pid=3313->guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320 execve guuid=e095651b-2100-0000-7418-8630f90c0000 pid=3321 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=e095651b-2100-0000-7418-8630f90c0000 pid=3321 execve guuid=22647a28-2100-0000-7418-8630fd0c0000 pid=3325 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=22647a28-2100-0000-7418-8630fd0c0000 pid=3325 execve guuid=b91c003c-2100-0000-7418-8630210d0000 pid=3361 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=b91c003c-2100-0000-7418-8630210d0000 pid=3361 execve guuid=0bcc443c-2100-0000-7418-8630230d0000 pid=3363 /home/sandbox/xnxnxnxnxnxnxnxnaarch64xnxn delete-file write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=0bcc443c-2100-0000-7418-8630230d0000 pid=3363 execve guuid=887251b3-2100-0000-7418-8630440e0000 pid=3652 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=887251b3-2100-0000-7418-8630440e0000 pid=3652 execve guuid=cf25a5b3-2100-0000-7418-8630450e0000 pid=3653 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=cf25a5b3-2100-0000-7418-8630450e0000 pid=3653 execve guuid=589ed1bb-2100-0000-7418-86304f0e0000 pid=3663 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=589ed1bb-2100-0000-7418-86304f0e0000 pid=3663 execve guuid=817fd4c8-2100-0000-7418-86305c0e0000 pid=3676 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=817fd4c8-2100-0000-7418-86305c0e0000 pid=3676 execve guuid=2f526ec9-2100-0000-7418-86305d0e0000 pid=3677 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=2f526ec9-2100-0000-7418-86305d0e0000 pid=3677 execve guuid=20a0edca-2100-0000-7418-8630630e0000 pid=3683 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=20a0edca-2100-0000-7418-8630630e0000 pid=3683 execve guuid=a2db34cb-2100-0000-7418-8630670e0000 pid=3687 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=a2db34cb-2100-0000-7418-8630670e0000 pid=3687 execve guuid=98db23d7-2100-0000-7418-86308c0e0000 pid=3724 /usr/bin/curl guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=98db23d7-2100-0000-7418-86308c0e0000 pid=3724 execve guuid=d62e22d9-2100-0000-7418-8630980e0000 pid=3736 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=d62e22d9-2100-0000-7418-8630980e0000 pid=3736 execve guuid=00c581d9-2100-0000-7418-86309a0e0000 pid=3738 /home/sandbox/xnxnxnxnxnxnxnxnloongarch64xnxn delete-file write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=00c581d9-2100-0000-7418-86309a0e0000 pid=3738 execve guuid=6f063adb-2100-0000-7418-8630a40e0000 pid=3748 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=6f063adb-2100-0000-7418-8630a40e0000 pid=3748 execve guuid=90c094db-2100-0000-7418-8630a60e0000 pid=3750 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=90c094db-2100-0000-7418-8630a60e0000 pid=3750 execve guuid=06333be7-2100-0000-7418-8630d10e0000 pid=3793 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=06333be7-2100-0000-7418-8630d10e0000 pid=3793 execve guuid=3b3fbbf2-2100-0000-7418-8630fc0e0000 pid=3836 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=3b3fbbf2-2100-0000-7418-8630fc0e0000 pid=3836 execve guuid=a12c30f3-2100-0000-7418-8630fd0e0000 pid=3837 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=a12c30f3-2100-0000-7418-8630fd0e0000 pid=3837 clone guuid=70bcf7f3-2100-0000-7418-8630010f0000 pid=3841 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=70bcf7f3-2100-0000-7418-8630010f0000 pid=3841 execve guuid=5971d4f4-2100-0000-7418-8630020f0000 pid=3842 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=5971d4f4-2100-0000-7418-8630020f0000 pid=3842 execve guuid=65fbeeff-2100-0000-7418-8630240f0000 pid=3876 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=65fbeeff-2100-0000-7418-8630240f0000 pid=3876 execve guuid=e32e890c-2200-0000-7418-8630530f0000 pid=3923 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=e32e890c-2200-0000-7418-8630530f0000 pid=3923 execve guuid=8541c70c-2200-0000-7418-8630550f0000 pid=3925 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=8541c70c-2200-0000-7418-8630550f0000 pid=3925 clone guuid=e6e2440d-2200-0000-7418-8630590f0000 pid=3929 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=e6e2440d-2200-0000-7418-8630590f0000 pid=3929 execve guuid=8061ac0d-2200-0000-7418-86305b0f0000 pid=3931 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=8061ac0d-2200-0000-7418-86305b0f0000 pid=3931 execve guuid=f22dc916-2200-0000-7418-8630820f0000 pid=3970 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=f22dc916-2200-0000-7418-8630820f0000 pid=3970 execve guuid=ebb7331e-2200-0000-7418-8630970f0000 pid=3991 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=ebb7331e-2200-0000-7418-8630970f0000 pid=3991 execve guuid=add8a31e-2200-0000-7418-8630990f0000 pid=3993 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=add8a31e-2200-0000-7418-8630990f0000 pid=3993 clone guuid=16df621f-2200-0000-7418-86309d0f0000 pid=3997 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=16df621f-2200-0000-7418-86309d0f0000 pid=3997 execve guuid=e4f7ab1f-2200-0000-7418-86309e0f0000 pid=3998 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=e4f7ab1f-2200-0000-7418-86309e0f0000 pid=3998 execve guuid=ca47b02b-2200-0000-7418-8630c10f0000 pid=4033 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=ca47b02b-2200-0000-7418-8630c10f0000 pid=4033 execve guuid=5aeb1e3b-2200-0000-7418-8630eb0f0000 pid=4075 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=5aeb1e3b-2200-0000-7418-8630eb0f0000 pid=4075 execve guuid=a5c16f3b-2200-0000-7418-8630ee0f0000 pid=4078 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=a5c16f3b-2200-0000-7418-8630ee0f0000 pid=4078 clone guuid=7f3f3d3c-2200-0000-7418-8630f10f0000 pid=4081 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=7f3f3d3c-2200-0000-7418-8630f10f0000 pid=4081 execve guuid=a41fa33c-2200-0000-7418-8630f50f0000 pid=4085 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=a41fa33c-2200-0000-7418-8630f50f0000 pid=4085 execve guuid=c406e245-2200-0000-7418-863012100000 pid=4114 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=c406e245-2200-0000-7418-863012100000 pid=4114 execve guuid=692f8491-2200-0000-7418-863006110000 pid=4358 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=692f8491-2200-0000-7418-863006110000 pid=4358 execve guuid=3442eb91-2200-0000-7418-863009110000 pid=4361 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=3442eb91-2200-0000-7418-863009110000 pid=4361 clone guuid=b9ebd292-2200-0000-7418-86300d110000 pid=4365 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=b9ebd292-2200-0000-7418-86300d110000 pid=4365 execve guuid=de451293-2200-0000-7418-86300e110000 pid=4366 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=de451293-2200-0000-7418-86300e110000 pid=4366 execve guuid=48763699-2200-0000-7418-863015110000 pid=4373 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=48763699-2200-0000-7418-863015110000 pid=4373 execve guuid=0bddfea4-2200-0000-7418-863042110000 pid=4418 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=0bddfea4-2200-0000-7418-863042110000 pid=4418 execve guuid=62188ca5-2200-0000-7418-863046110000 pid=4422 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=62188ca5-2200-0000-7418-863046110000 pid=4422 clone guuid=e84fbda7-2200-0000-7418-863050110000 pid=4432 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=e84fbda7-2200-0000-7418-863050110000 pid=4432 execve guuid=ad1d18a8-2200-0000-7418-863052110000 pid=4434 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=ad1d18a8-2200-0000-7418-863052110000 pid=4434 execve guuid=c58c89b2-2200-0000-7418-863077110000 pid=4471 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=c58c89b2-2200-0000-7418-863077110000 pid=4471 execve guuid=192348c0-2200-0000-7418-8630a8110000 pid=4520 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=192348c0-2200-0000-7418-8630a8110000 pid=4520 execve guuid=dddea3c0-2200-0000-7418-8630aa110000 pid=4522 /home/sandbox/xnxnxnxnxnxnxnxnriscv64xnxn delete-file write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=dddea3c0-2200-0000-7418-8630aa110000 pid=4522 execve guuid=2029e3c1-2200-0000-7418-8630b2110000 pid=4530 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=2029e3c1-2200-0000-7418-8630b2110000 pid=4530 execve guuid=c4a74ec2-2200-0000-7418-8630b4110000 pid=4532 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=c4a74ec2-2200-0000-7418-8630b4110000 pid=4532 execve guuid=1702c7cc-2200-0000-7418-8630d1110000 pid=4561 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=1702c7cc-2200-0000-7418-8630d1110000 pid=4561 execve guuid=c32ae4d9-2200-0000-7418-8630ff110000 pid=4607 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=c32ae4d9-2200-0000-7418-8630ff110000 pid=4607 execve guuid=33826dda-2200-0000-7418-863000120000 pid=4608 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=33826dda-2200-0000-7418-863000120000 pid=4608 clone guuid=712856db-2200-0000-7418-863003120000 pid=4611 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=712856db-2200-0000-7418-863003120000 pid=4611 execve guuid=cda0c2db-2200-0000-7418-863005120000 pid=4613 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=cda0c2db-2200-0000-7418-863005120000 pid=4613 execve guuid=0838b7e5-2200-0000-7418-86302d120000 pid=4653 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=0838b7e5-2200-0000-7418-86302d120000 pid=4653 execve guuid=ca670cf2-2200-0000-7418-86304b120000 pid=4683 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=ca670cf2-2200-0000-7418-86304b120000 pid=4683 execve guuid=5e7976f2-2200-0000-7418-86304d120000 pid=4685 /usr/bin/dash guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=5e7976f2-2200-0000-7418-86304d120000 pid=4685 clone guuid=4e3f8bf3-2200-0000-7418-863050120000 pid=4688 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=4e3f8bf3-2200-0000-7418-863050120000 pid=4688 execve guuid=ad1805f4-2200-0000-7418-863052120000 pid=4690 /usr/bin/wget net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=ad1805f4-2200-0000-7418-863052120000 pid=4690 execve guuid=7a7b11fd-2200-0000-7418-863068120000 pid=4712 /usr/bin/curl net send-data write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=7a7b11fd-2200-0000-7418-863068120000 pid=4712 execve guuid=429fac0a-2300-0000-7418-863093120000 pid=4755 /usr/bin/chmod guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=429fac0a-2300-0000-7418-863093120000 pid=4755 execve guuid=d0d1d90b-2300-0000-7418-863097120000 pid=4759 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn delete-file write-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=d0d1d90b-2300-0000-7418-863097120000 pid=4759 execve guuid=2f5c2f0d-2300-0000-7418-8630a0120000 pid=4768 /usr/bin/rm delete-file guuid=1e6afa1a-2100-0000-7418-8630f80c0000 pid=3320->guuid=2f5c2f0d-2300-0000-7418-8630a0120000 pid=4768 execve 06f1d7fc-fa3d-5811-a626-d1a59e484d0e 193.32.208.35:80 guuid=e095651b-2100-0000-7418-8630f90c0000 pid=3321->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 160B guuid=22647a28-2100-0000-7418-8630fd0c0000 pid=3325->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 109B guuid=bee9cfb1-2100-0000-7418-86303c0e0000 pid=3644 /home/sandbox/xnxnxnxnxnxnxnxnaarch64xnxn guuid=0bcc443c-2100-0000-7418-8630230d0000 pid=3363->guuid=bee9cfb1-2100-0000-7418-86303c0e0000 pid=3644 clone guuid=cf25a5b3-2100-0000-7418-8630450e0000 pid=3653->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 157B guuid=589ed1bb-2100-0000-7418-86304f0e0000 pid=3663->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 106B guuid=797bdcca-2100-0000-7418-8630610e0000 pid=3681 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=2f526ec9-2100-0000-7418-86305d0e0000 pid=3677->guuid=797bdcca-2100-0000-7418-8630610e0000 pid=3681 clone guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3682 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn net send-data zombie guuid=797bdcca-2100-0000-7418-8630610e0000 pid=3681->guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3682 clone bec6467f-939d-5f5e-9333-f8b5b559f6ff 193.32.208.35:54128 guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3682->bec6467f-939d-5f5e-9333-f8b5b559f6ff con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3682->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 33B guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3688 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3682->guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3688 clone guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3689 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn zombie guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3682->guuid=aa3deaca-2100-0000-7418-8630620e0000 pid=3689 clone guuid=a2db34cb-2100-0000-7418-8630670e0000 pid=3687->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 164B guuid=c61427da-2100-0000-7418-86309e0e0000 pid=3742 /home/sandbox/xnxnxnxnxnxnxnxnloongarch64xnxn guuid=00c581d9-2100-0000-7418-86309a0e0000 pid=3738->guuid=c61427da-2100-0000-7418-86309e0e0000 pid=3742 clone guuid=90c094db-2100-0000-7418-8630a60e0000 pid=3750->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 157B guuid=06333be7-2100-0000-7418-8630d10e0000 pid=3793->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 106B guuid=5971d4f4-2100-0000-7418-8630020f0000 pid=3842->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 163B guuid=65fbeeff-2100-0000-7418-8630240f0000 pid=3876->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 112B guuid=8061ac0d-2200-0000-7418-86305b0f0000 pid=3931->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 157B guuid=f22dc916-2200-0000-7418-8630820f0000 pid=3970->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 106B guuid=e4f7ab1f-2200-0000-7418-86309e0f0000 pid=3998->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 157B guuid=ca47b02b-2200-0000-7418-8630c10f0000 pid=4033->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 106B guuid=a41fa33c-2200-0000-7418-8630f50f0000 pid=4085->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 160B guuid=c406e245-2200-0000-7418-863012100000 pid=4114->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 109B guuid=de451293-2200-0000-7418-86300e110000 pid=4366->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 160B guuid=48763699-2200-0000-7418-863015110000 pid=4373->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 109B guuid=ad1d18a8-2200-0000-7418-863052110000 pid=4434->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 160B guuid=c58c89b2-2200-0000-7418-863077110000 pid=4471->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 109B guuid=b56629c1-2200-0000-7418-8630ad110000 pid=4525 /home/sandbox/xnxnxnxnxnxnxnxnriscv64xnxn guuid=dddea3c0-2200-0000-7418-8630aa110000 pid=4522->guuid=b56629c1-2200-0000-7418-8630ad110000 pid=4525 clone guuid=c4a74ec2-2200-0000-7418-8630b4110000 pid=4532->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 156B guuid=1702c7cc-2200-0000-7418-8630d1110000 pid=4561->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 105B guuid=cda0c2db-2200-0000-7418-863005120000 pid=4613->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 156B guuid=0838b7e5-2200-0000-7418-86302d120000 pid=4653->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 105B guuid=ad1805f4-2200-0000-7418-863052120000 pid=4690->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 159B guuid=7a7b11fd-2200-0000-7418-863068120000 pid=4712->06f1d7fc-fa3d-5811-a626-d1a59e484d0e send: 108B guuid=b9eb400c-2300-0000-7418-86309a120000 pid=4762 /tmp/filebBT5RW write-file guuid=d0d1d90b-2300-0000-7418-863097120000 pid=4759->guuid=b9eb400c-2300-0000-7418-86309a120000 pid=4762 execve guuid=ed511b0d-2300-0000-7418-86309e120000 pid=4766 /tmp/filebBT5RW zombie guuid=b9eb400c-2300-0000-7418-86309a120000 pid=4762->guuid=ed511b0d-2300-0000-7418-86309e120000 pid=4766 clone guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4767 /tmp/filebBT5RW delete-file net send-data zombie guuid=ed511b0d-2300-0000-7418-86309e120000 pid=4766->guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4767 clone guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4767->bec6467f-939d-5f5e-9333-f8b5b559f6ff con guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4767->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 33B guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4772 /tmp/filebBT5RW guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4767->guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4772 clone guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4773 /tmp/filebBT5RW zombie guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4767->guuid=9f3b250d-2300-0000-7418-86309f120000 pid=4773 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2026-05-05 03:08:34 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ladvix

sh f778e9f251fa6fa4fabdef19a275b16fa4576706f429f6308abce8a8a2fed126

(this sample)

  
Delivery method
Distributed via web download

Comments