MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 faccc7751be9fba6dbb999e62d6cd650d98d6c4e76b646f7b445d1881555b606. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: faccc7751be9fba6dbb999e62d6cd650d98d6c4e76b646f7b445d1881555b606
SHA3-384 hash: c319e7c6760387cd2bc69cc0620edcebd56caad6294ddbde8c9e1b74634e3d410ce0c00f4fb3bae6f4ab3eb8dffb0e5e
SHA1 hash: d0d4da6ac45b2da56e9b6452df2fbf8e07c13ac5
MD5 hash: d3bf11fdd27aca925078e13339a9c899
humanhash: comet-ten-april-hamper
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-07 02:44:24 UTC
Last seen:2026-06-07 03:21:47 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaHiCe7ZI1U4t9+CN7:e9Qp+MsHVe7u19+g7
TLSH T14F0188CF8101C7608486E89F66E761C0B411C3DB29464BB87E9C983DFFE97597015EA8
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/SGJBn/an/aelf ua-wget
http://188.132.232.81/8NaTn/an/aelf ua-wget
http://188.132.232.81/mqkn/an/aelf ua-wget
http://188.132.232.81/7RwIn/an/aelf ua-wget
http://188.132.232.81/TIon/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-06T23:53:00Z UTC
Last seen:
2026-06-07T00:12:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f1f0a218-1700-0000-eae5-ad7aaa0d0000 pid=3498 /usr/bin/sudo guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505 /tmp/sample.bin write-file guuid=f1f0a218-1700-0000-eae5-ad7aaa0d0000 pid=3498->guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505 execve guuid=8c05e51a-1700-0000-eae5-ad7ab20d0000 pid=3506 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8c05e51a-1700-0000-eae5-ad7ab20d0000 pid=3506 execve guuid=e30e481b-1700-0000-eae5-ad7ab40d0000 pid=3508 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=e30e481b-1700-0000-eae5-ad7ab40d0000 pid=3508 execve guuid=3e34c11b-1700-0000-eae5-ad7ab60d0000 pid=3510 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3e34c11b-1700-0000-eae5-ad7ab60d0000 pid=3510 execve guuid=b6672a1c-1700-0000-eae5-ad7ab90d0000 pid=3513 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=b6672a1c-1700-0000-eae5-ad7ab90d0000 pid=3513 execve guuid=d885961c-1700-0000-eae5-ad7abc0d0000 pid=3516 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=d885961c-1700-0000-eae5-ad7abc0d0000 pid=3516 execve guuid=c818f11c-1700-0000-eae5-ad7abe0d0000 pid=3518 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=c818f11c-1700-0000-eae5-ad7abe0d0000 pid=3518 execve guuid=2458541d-1700-0000-eae5-ad7ac00d0000 pid=3520 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=2458541d-1700-0000-eae5-ad7ac00d0000 pid=3520 execve guuid=3242b21d-1700-0000-eae5-ad7ac20d0000 pid=3522 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3242b21d-1700-0000-eae5-ad7ac20d0000 pid=3522 execve guuid=9d4f141e-1700-0000-eae5-ad7ac50d0000 pid=3525 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=9d4f141e-1700-0000-eae5-ad7ac50d0000 pid=3525 execve guuid=0a89771e-1700-0000-eae5-ad7ac70d0000 pid=3527 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0a89771e-1700-0000-eae5-ad7ac70d0000 pid=3527 execve guuid=8b3fcd1e-1700-0000-eae5-ad7ac90d0000 pid=3529 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8b3fcd1e-1700-0000-eae5-ad7ac90d0000 pid=3529 execve guuid=0d3b241f-1700-0000-eae5-ad7acb0d0000 pid=3531 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0d3b241f-1700-0000-eae5-ad7acb0d0000 pid=3531 execve guuid=5a5f8d1f-1700-0000-eae5-ad7ace0d0000 pid=3534 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=5a5f8d1f-1700-0000-eae5-ad7ace0d0000 pid=3534 execve guuid=06398020-1700-0000-eae5-ad7ad10d0000 pid=3537 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=06398020-1700-0000-eae5-ad7ad10d0000 pid=3537 execve guuid=7c021b21-1700-0000-eae5-ad7ad30d0000 pid=3539 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=7c021b21-1700-0000-eae5-ad7ad30d0000 pid=3539 execve guuid=041c7321-1700-0000-eae5-ad7ad50d0000 pid=3541 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=041c7321-1700-0000-eae5-ad7ad50d0000 pid=3541 execve guuid=dc50d221-1700-0000-eae5-ad7ad80d0000 pid=3544 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=dc50d221-1700-0000-eae5-ad7ad80d0000 pid=3544 execve guuid=dc833022-1700-0000-eae5-ad7ada0d0000 pid=3546 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=dc833022-1700-0000-eae5-ad7ada0d0000 pid=3546 execve guuid=4df29722-1700-0000-eae5-ad7adc0d0000 pid=3548 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=4df29722-1700-0000-eae5-ad7adc0d0000 pid=3548 execve guuid=0fb0f322-1700-0000-eae5-ad7ade0d0000 pid=3550 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0fb0f322-1700-0000-eae5-ad7ade0d0000 pid=3550 execve guuid=08745523-1700-0000-eae5-ad7ae10d0000 pid=3553 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=08745523-1700-0000-eae5-ad7ae10d0000 pid=3553 execve guuid=45edb023-1700-0000-eae5-ad7ae30d0000 pid=3555 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=45edb023-1700-0000-eae5-ad7ae30d0000 pid=3555 execve guuid=c8bc1724-1700-0000-eae5-ad7ae50d0000 pid=3557 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=c8bc1724-1700-0000-eae5-ad7ae50d0000 pid=3557 execve guuid=a4cd9e24-1700-0000-eae5-ad7ae80d0000 pid=3560 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a4cd9e24-1700-0000-eae5-ad7ae80d0000 pid=3560 execve guuid=7e752a25-1700-0000-eae5-ad7aeb0d0000 pid=3563 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=7e752a25-1700-0000-eae5-ad7aeb0d0000 pid=3563 execve guuid=c9a2b225-1700-0000-eae5-ad7aee0d0000 pid=3566 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=c9a2b225-1700-0000-eae5-ad7aee0d0000 pid=3566 execve guuid=30833726-1700-0000-eae5-ad7af10d0000 pid=3569 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=30833726-1700-0000-eae5-ad7af10d0000 pid=3569 execve guuid=ef72ba26-1700-0000-eae5-ad7af40d0000 pid=3572 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=ef72ba26-1700-0000-eae5-ad7af40d0000 pid=3572 execve guuid=98cb2f27-1700-0000-eae5-ad7af50d0000 pid=3573 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=98cb2f27-1700-0000-eae5-ad7af50d0000 pid=3573 execve guuid=47ad8727-1700-0000-eae5-ad7af70d0000 pid=3575 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=47ad8727-1700-0000-eae5-ad7af70d0000 pid=3575 execve guuid=e69dde27-1700-0000-eae5-ad7af90d0000 pid=3577 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=e69dde27-1700-0000-eae5-ad7af90d0000 pid=3577 execve guuid=ddea3828-1700-0000-eae5-ad7afb0d0000 pid=3579 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=ddea3828-1700-0000-eae5-ad7afb0d0000 pid=3579 execve guuid=48bb9528-1700-0000-eae5-ad7afd0d0000 pid=3581 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=48bb9528-1700-0000-eae5-ad7afd0d0000 pid=3581 execve guuid=e5c55e29-1700-0000-eae5-ad7a020e0000 pid=3586 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=e5c55e29-1700-0000-eae5-ad7a020e0000 pid=3586 execve guuid=a055bd29-1700-0000-eae5-ad7a060e0000 pid=3590 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a055bd29-1700-0000-eae5-ad7a060e0000 pid=3590 execve guuid=fa2b162a-1700-0000-eae5-ad7a070e0000 pid=3591 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=fa2b162a-1700-0000-eae5-ad7a070e0000 pid=3591 execve guuid=3a16742a-1700-0000-eae5-ad7a090e0000 pid=3593 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3a16742a-1700-0000-eae5-ad7a090e0000 pid=3593 execve guuid=3669d42a-1700-0000-eae5-ad7a0b0e0000 pid=3595 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3669d42a-1700-0000-eae5-ad7a0b0e0000 pid=3595 execve guuid=8fd3392b-1700-0000-eae5-ad7a0c0e0000 pid=3596 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8fd3392b-1700-0000-eae5-ad7a0c0e0000 pid=3596 execve guuid=2790a42b-1700-0000-eae5-ad7a0f0e0000 pid=3599 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=2790a42b-1700-0000-eae5-ad7a0f0e0000 pid=3599 execve guuid=bd96032c-1700-0000-eae5-ad7a110e0000 pid=3601 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=bd96032c-1700-0000-eae5-ad7a110e0000 pid=3601 execve guuid=066a6d2c-1700-0000-eae5-ad7a140e0000 pid=3604 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=066a6d2c-1700-0000-eae5-ad7a140e0000 pid=3604 execve guuid=ee26cb2c-1700-0000-eae5-ad7a150e0000 pid=3605 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=ee26cb2c-1700-0000-eae5-ad7a150e0000 pid=3605 execve guuid=bd86312d-1700-0000-eae5-ad7a180e0000 pid=3608 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=bd86312d-1700-0000-eae5-ad7a180e0000 pid=3608 execve guuid=c309942d-1700-0000-eae5-ad7a1a0e0000 pid=3610 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=c309942d-1700-0000-eae5-ad7a1a0e0000 pid=3610 execve guuid=06721c2e-1700-0000-eae5-ad7a1c0e0000 pid=3612 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=06721c2e-1700-0000-eae5-ad7a1c0e0000 pid=3612 execve guuid=01767e2e-1700-0000-eae5-ad7a1f0e0000 pid=3615 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=01767e2e-1700-0000-eae5-ad7a1f0e0000 pid=3615 execve guuid=ce6bee2e-1700-0000-eae5-ad7a210e0000 pid=3617 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=ce6bee2e-1700-0000-eae5-ad7a210e0000 pid=3617 execve guuid=730a542f-1700-0000-eae5-ad7a230e0000 pid=3619 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=730a542f-1700-0000-eae5-ad7a230e0000 pid=3619 execve guuid=cce5ab2f-1700-0000-eae5-ad7a250e0000 pid=3621 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=cce5ab2f-1700-0000-eae5-ad7a250e0000 pid=3621 execve guuid=67cdfb2f-1700-0000-eae5-ad7a270e0000 pid=3623 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=67cdfb2f-1700-0000-eae5-ad7a270e0000 pid=3623 execve guuid=9d3f5930-1700-0000-eae5-ad7a290e0000 pid=3625 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=9d3f5930-1700-0000-eae5-ad7a290e0000 pid=3625 execve guuid=4472b830-1700-0000-eae5-ad7a2b0e0000 pid=3627 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=4472b830-1700-0000-eae5-ad7a2b0e0000 pid=3627 execve guuid=07d51431-1700-0000-eae5-ad7a2d0e0000 pid=3629 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=07d51431-1700-0000-eae5-ad7a2d0e0000 pid=3629 execve guuid=3a4b6131-1700-0000-eae5-ad7a2f0e0000 pid=3631 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3a4b6131-1700-0000-eae5-ad7a2f0e0000 pid=3631 execve guuid=31f7bd31-1700-0000-eae5-ad7a310e0000 pid=3633 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=31f7bd31-1700-0000-eae5-ad7a310e0000 pid=3633 execve guuid=97a91a32-1700-0000-eae5-ad7a330e0000 pid=3635 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=97a91a32-1700-0000-eae5-ad7a330e0000 pid=3635 execve guuid=75647432-1700-0000-eae5-ad7a360e0000 pid=3638 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=75647432-1700-0000-eae5-ad7a360e0000 pid=3638 execve guuid=b8e5cd32-1700-0000-eae5-ad7a380e0000 pid=3640 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=b8e5cd32-1700-0000-eae5-ad7a380e0000 pid=3640 execve guuid=738b2f33-1700-0000-eae5-ad7a3a0e0000 pid=3642 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=738b2f33-1700-0000-eae5-ad7a3a0e0000 pid=3642 execve guuid=e4538f33-1700-0000-eae5-ad7a3d0e0000 pid=3645 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=e4538f33-1700-0000-eae5-ad7a3d0e0000 pid=3645 execve guuid=2552ed33-1700-0000-eae5-ad7a3f0e0000 pid=3647 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=2552ed33-1700-0000-eae5-ad7a3f0e0000 pid=3647 execve guuid=54248134-1700-0000-eae5-ad7a420e0000 pid=3650 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=54248134-1700-0000-eae5-ad7a420e0000 pid=3650 execve guuid=4f7c1e35-1700-0000-eae5-ad7a450e0000 pid=3653 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=4f7c1e35-1700-0000-eae5-ad7a450e0000 pid=3653 execve guuid=e3b9bb35-1700-0000-eae5-ad7a470e0000 pid=3655 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=e3b9bb35-1700-0000-eae5-ad7a470e0000 pid=3655 execve guuid=b6011636-1700-0000-eae5-ad7a4a0e0000 pid=3658 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=b6011636-1700-0000-eae5-ad7a4a0e0000 pid=3658 execve guuid=f5c16736-1700-0000-eae5-ad7a4b0e0000 pid=3659 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=f5c16736-1700-0000-eae5-ad7a4b0e0000 pid=3659 execve guuid=32aebe36-1700-0000-eae5-ad7a4d0e0000 pid=3661 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=32aebe36-1700-0000-eae5-ad7a4d0e0000 pid=3661 execve guuid=47d21937-1700-0000-eae5-ad7a4f0e0000 pid=3663 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=47d21937-1700-0000-eae5-ad7a4f0e0000 pid=3663 execve guuid=7e177137-1700-0000-eae5-ad7a510e0000 pid=3665 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=7e177137-1700-0000-eae5-ad7a510e0000 pid=3665 execve guuid=95d6cd37-1700-0000-eae5-ad7a530e0000 pid=3667 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=95d6cd37-1700-0000-eae5-ad7a530e0000 pid=3667 execve guuid=00cd2738-1700-0000-eae5-ad7a540e0000 pid=3668 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=00cd2738-1700-0000-eae5-ad7a540e0000 pid=3668 execve guuid=20298938-1700-0000-eae5-ad7a560e0000 pid=3670 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=20298938-1700-0000-eae5-ad7a560e0000 pid=3670 execve guuid=eff81c39-1700-0000-eae5-ad7a590e0000 pid=3673 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=eff81c39-1700-0000-eae5-ad7a590e0000 pid=3673 execve guuid=55927d39-1700-0000-eae5-ad7a5b0e0000 pid=3675 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=55927d39-1700-0000-eae5-ad7a5b0e0000 pid=3675 execve guuid=81b9e639-1700-0000-eae5-ad7a5d0e0000 pid=3677 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=81b9e639-1700-0000-eae5-ad7a5d0e0000 pid=3677 execve guuid=82394d3a-1700-0000-eae5-ad7a600e0000 pid=3680 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=82394d3a-1700-0000-eae5-ad7a600e0000 pid=3680 execve guuid=c57cad3a-1700-0000-eae5-ad7a620e0000 pid=3682 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=c57cad3a-1700-0000-eae5-ad7a620e0000 pid=3682 execve guuid=f786133b-1700-0000-eae5-ad7a650e0000 pid=3685 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=f786133b-1700-0000-eae5-ad7a650e0000 pid=3685 execve guuid=6885773b-1700-0000-eae5-ad7a670e0000 pid=3687 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=6885773b-1700-0000-eae5-ad7a670e0000 pid=3687 execve guuid=0febdb3b-1700-0000-eae5-ad7a6b0e0000 pid=3691 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0febdb3b-1700-0000-eae5-ad7a6b0e0000 pid=3691 execve guuid=38053d3c-1700-0000-eae5-ad7a6c0e0000 pid=3692 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=38053d3c-1700-0000-eae5-ad7a6c0e0000 pid=3692 execve guuid=bddba63c-1700-0000-eae5-ad7a6e0e0000 pid=3694 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=bddba63c-1700-0000-eae5-ad7a6e0e0000 pid=3694 execve guuid=3b2b153d-1700-0000-eae5-ad7a710e0000 pid=3697 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3b2b153d-1700-0000-eae5-ad7a710e0000 pid=3697 execve guuid=ac30763d-1700-0000-eae5-ad7a750e0000 pid=3701 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=ac30763d-1700-0000-eae5-ad7a750e0000 pid=3701 execve guuid=9516da3d-1700-0000-eae5-ad7a790e0000 pid=3705 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=9516da3d-1700-0000-eae5-ad7a790e0000 pid=3705 execve guuid=0eb33e3e-1700-0000-eae5-ad7a7a0e0000 pid=3706 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0eb33e3e-1700-0000-eae5-ad7a7a0e0000 pid=3706 execve guuid=03419c3e-1700-0000-eae5-ad7a7e0e0000 pid=3710 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=03419c3e-1700-0000-eae5-ad7a7e0e0000 pid=3710 execve guuid=a991063f-1700-0000-eae5-ad7a800e0000 pid=3712 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a991063f-1700-0000-eae5-ad7a800e0000 pid=3712 execve guuid=5cae733f-1700-0000-eae5-ad7a820e0000 pid=3714 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=5cae733f-1700-0000-eae5-ad7a820e0000 pid=3714 execve guuid=2ef30040-1700-0000-eae5-ad7a850e0000 pid=3717 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=2ef30040-1700-0000-eae5-ad7a850e0000 pid=3717 execve guuid=07066340-1700-0000-eae5-ad7a880e0000 pid=3720 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=07066340-1700-0000-eae5-ad7a880e0000 pid=3720 execve guuid=1ef0c240-1700-0000-eae5-ad7a8a0e0000 pid=3722 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=1ef0c240-1700-0000-eae5-ad7a8a0e0000 pid=3722 execve guuid=d7e76f41-1700-0000-eae5-ad7a8f0e0000 pid=3727 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=d7e76f41-1700-0000-eae5-ad7a8f0e0000 pid=3727 execve guuid=9776e041-1700-0000-eae5-ad7a930e0000 pid=3731 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=9776e041-1700-0000-eae5-ad7a930e0000 pid=3731 execve guuid=45c83f42-1700-0000-eae5-ad7a940e0000 pid=3732 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=45c83f42-1700-0000-eae5-ad7a940e0000 pid=3732 execve guuid=03949f42-1700-0000-eae5-ad7a960e0000 pid=3734 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=03949f42-1700-0000-eae5-ad7a960e0000 pid=3734 execve guuid=2fcf0243-1700-0000-eae5-ad7a990e0000 pid=3737 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=2fcf0243-1700-0000-eae5-ad7a990e0000 pid=3737 execve guuid=2b526243-1700-0000-eae5-ad7a9b0e0000 pid=3739 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=2b526243-1700-0000-eae5-ad7a9b0e0000 pid=3739 execve guuid=5adcbe43-1700-0000-eae5-ad7a9d0e0000 pid=3741 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=5adcbe43-1700-0000-eae5-ad7a9d0e0000 pid=3741 execve guuid=b1012444-1700-0000-eae5-ad7aa00e0000 pid=3744 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=b1012444-1700-0000-eae5-ad7aa00e0000 pid=3744 execve guuid=c2ea8144-1700-0000-eae5-ad7aa10e0000 pid=3745 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=c2ea8144-1700-0000-eae5-ad7aa10e0000 pid=3745 execve guuid=4b32df44-1700-0000-eae5-ad7aa30e0000 pid=3747 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=4b32df44-1700-0000-eae5-ad7aa30e0000 pid=3747 execve guuid=8a663c45-1700-0000-eae5-ad7aa70e0000 pid=3751 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8a663c45-1700-0000-eae5-ad7aa70e0000 pid=3751 execve guuid=8230a645-1700-0000-eae5-ad7aaa0e0000 pid=3754 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8230a645-1700-0000-eae5-ad7aaa0e0000 pid=3754 execve guuid=4ac53846-1700-0000-eae5-ad7aad0e0000 pid=3757 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=4ac53846-1700-0000-eae5-ad7aad0e0000 pid=3757 execve guuid=055dc846-1700-0000-eae5-ad7ab00e0000 pid=3760 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=055dc846-1700-0000-eae5-ad7ab00e0000 pid=3760 execve guuid=23915447-1700-0000-eae5-ad7ab30e0000 pid=3763 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=23915447-1700-0000-eae5-ad7ab30e0000 pid=3763 execve guuid=344bed47-1700-0000-eae5-ad7ab50e0000 pid=3765 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=344bed47-1700-0000-eae5-ad7ab50e0000 pid=3765 execve guuid=a6097348-1700-0000-eae5-ad7ab60e0000 pid=3766 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a6097348-1700-0000-eae5-ad7ab60e0000 pid=3766 execve guuid=139cd648-1700-0000-eae5-ad7ab80e0000 pid=3768 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=139cd648-1700-0000-eae5-ad7ab80e0000 pid=3768 execve guuid=18833b49-1700-0000-eae5-ad7abb0e0000 pid=3771 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=18833b49-1700-0000-eae5-ad7abb0e0000 pid=3771 execve guuid=408a9e49-1700-0000-eae5-ad7abf0e0000 pid=3775 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=408a9e49-1700-0000-eae5-ad7abf0e0000 pid=3775 execve guuid=a884054a-1700-0000-eae5-ad7ac10e0000 pid=3777 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a884054a-1700-0000-eae5-ad7ac10e0000 pid=3777 execve guuid=74b16d4a-1700-0000-eae5-ad7ac30e0000 pid=3779 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=74b16d4a-1700-0000-eae5-ad7ac30e0000 pid=3779 execve guuid=8895cd4a-1700-0000-eae5-ad7ac60e0000 pid=3782 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8895cd4a-1700-0000-eae5-ad7ac60e0000 pid=3782 execve guuid=4f313f4b-1700-0000-eae5-ad7ac80e0000 pid=3784 /usr/bin/ls guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=4f313f4b-1700-0000-eae5-ad7ac80e0000 pid=3784 execve guuid=3758ad4b-1700-0000-eae5-ad7aca0e0000 pid=3786 /usr/bin/rm guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3758ad4b-1700-0000-eae5-ad7aca0e0000 pid=3786 execve guuid=8446f94b-1700-0000-eae5-ad7acb0e0000 pid=3787 /usr/bin/wget net send-data write-file guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=8446f94b-1700-0000-eae5-ad7acb0e0000 pid=3787 execve guuid=a3eba21d-1800-0000-eae5-ad7a55110000 pid=4437 /usr/bin/chmod guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a3eba21d-1800-0000-eae5-ad7a55110000 pid=4437 execve guuid=0b4d371e-1800-0000-eae5-ad7a58110000 pid=4440 /usr/bin/dash guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0b4d371e-1800-0000-eae5-ad7a58110000 pid=4440 clone guuid=7ff1d220-1800-0000-eae5-ad7a62110000 pid=4450 /usr/bin/rm guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=7ff1d220-1800-0000-eae5-ad7a62110000 pid=4450 execve guuid=442f1321-1800-0000-eae5-ad7a65110000 pid=4453 /usr/bin/wget net send-data write-file guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=442f1321-1800-0000-eae5-ad7a65110000 pid=4453 execve guuid=0da6b426-1900-0000-eae5-ad7adc130000 pid=5084 /usr/bin/chmod guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=0da6b426-1900-0000-eae5-ad7adc130000 pid=5084 execve guuid=45393027-1900-0000-eae5-ad7ade130000 pid=5086 /usr/bin/dash guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=45393027-1900-0000-eae5-ad7ade130000 pid=5086 clone guuid=12badc29-1900-0000-eae5-ad7ae6130000 pid=5094 /usr/bin/rm guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=12badc29-1900-0000-eae5-ad7ae6130000 pid=5094 execve guuid=3bc4282a-1900-0000-eae5-ad7ae8130000 pid=5096 /usr/bin/wget net send-data write-file guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=3bc4282a-1900-0000-eae5-ad7ae8130000 pid=5096 execve guuid=d654bd5a-1900-0000-eae5-ad7a58140000 pid=5208 /usr/bin/chmod guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=d654bd5a-1900-0000-eae5-ad7a58140000 pid=5208 execve guuid=cd5c1f5b-1900-0000-eae5-ad7a5a140000 pid=5210 /usr/bin/dash guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=cd5c1f5b-1900-0000-eae5-ad7a5a140000 pid=5210 clone guuid=68aab75b-1900-0000-eae5-ad7a60140000 pid=5216 /usr/bin/rm guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=68aab75b-1900-0000-eae5-ad7a60140000 pid=5216 execve guuid=bf00fb5b-1900-0000-eae5-ad7a61140000 pid=5217 /usr/bin/wget net send-data write-file guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=bf00fb5b-1900-0000-eae5-ad7a61140000 pid=5217 execve guuid=79ece326-1b00-0000-eae5-ad7af3140000 pid=5363 /usr/bin/chmod guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=79ece326-1b00-0000-eae5-ad7af3140000 pid=5363 execve guuid=f9a61a27-1b00-0000-eae5-ad7af4140000 pid=5364 /usr/bin/dash guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=f9a61a27-1b00-0000-eae5-ad7af4140000 pid=5364 clone guuid=7f8cb227-1b00-0000-eae5-ad7af6140000 pid=5366 /usr/bin/rm guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=7f8cb227-1b00-0000-eae5-ad7af6140000 pid=5366 execve guuid=600cf627-1b00-0000-eae5-ad7af7140000 pid=5367 /usr/bin/wget net send-data write-file guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=600cf627-1b00-0000-eae5-ad7af7140000 pid=5367 execve guuid=43b692df-1c00-0000-eae5-ad7a18150000 pid=5400 /usr/bin/chmod guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=43b692df-1c00-0000-eae5-ad7a18150000 pid=5400 execve guuid=da33d6df-1c00-0000-eae5-ad7a19150000 pid=5401 /usr/bin/dash guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=da33d6df-1c00-0000-eae5-ad7a19150000 pid=5401 clone guuid=a46d72e0-1c00-0000-eae5-ad7a1b150000 pid=5403 /usr/bin/rm delete-file guuid=30e19f1a-1700-0000-eae5-ad7ab10d0000 pid=3505->guuid=a46d72e0-1c00-0000-eae5-ad7a1b150000 pid=5403 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=8446f94b-1700-0000-eae5-ad7acb0e0000 pid=3787->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=442f1321-1800-0000-eae5-ad7a65110000 pid=4453->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=3bc4282a-1900-0000-eae5-ad7ae8130000 pid=5096->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=bf00fb5b-1900-0000-eae5-ad7a61140000 pid=5217->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=600cf627-1b00-0000-eae5-ad7af7140000 pid=5367->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-07 03:18:18 UTC
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh faccc7751be9fba6dbb999e62d6cd650d98d6c4e76b646f7b445d1881555b606

(this sample)

  
Delivery method
Distributed via web download

Comments