MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 01d44bd0e993541e1182882a4fa010de1b7ae9dbb38dd8ab10ff63c5b9889115. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 01d44bd0e993541e1182882a4fa010de1b7ae9dbb38dd8ab10ff63c5b9889115
SHA3-384 hash: d3aca97b159472848a27f1a2a03a2208371a722c2ef4685d4baa1872ac30a3c30e198dfe2a8c3a72519d5ffd561e3240
SHA1 hash: b917680733b230ef8eb7306ea6129176029325a6
MD5 hash: c842306a7dbff7822b37513f317b0a69
humanhash: low-bacon-california-yankee
File name:wr.php
Download: download sample
File size:27'042 bytes
First seen:2026-07-24 07:21:56 UTC
Last seen:2026-07-25 05:40:13 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 768:c8vCB+25j6es8Rq9FYpMSUpi+20qUpi+20YQX:c8l25Jcd2QX
TLSH T1D0C27C966A967C44BDC98A3E4CBD2B0D6DF5C3D1224942AC3D8B3C71DC11FACD618B1A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.119.69.4/z/post/noroot.phpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-24T06:06:00Z UTC
Last seen:
2026-07-24T09:30:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c11f29e5-1800-0000-e794-bd36de0b0000 pid=3038 /usr/bin/sudo guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039 /tmp/sample.bin guuid=c11f29e5-1800-0000-e794-bd36de0b0000 pid=3038->guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039 execve guuid=854c36e8-1800-0000-e794-bd36e00b0000 pid=3040 /usr/bin/bash guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=854c36e8-1800-0000-e794-bd36e00b0000 pid=3040 clone guuid=834e3ee8-1800-0000-e794-bd36e10b0000 pid=3041 /usr/bin/base64 guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=834e3ee8-1800-0000-e794-bd36e10b0000 pid=3041 execve guuid=259b49e8-1800-0000-e794-bd36e20b0000 pid=3042 /usr/bin/bash guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=259b49e8-1800-0000-e794-bd36e20b0000 pid=3042 clone guuid=c18602e9-1800-0000-e794-bd36e30b0000 pid=3043 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=c18602e9-1800-0000-e794-bd36e30b0000 pid=3043 execve guuid=934688e9-1800-0000-e794-bd36e40b0000 pid=3044 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=934688e9-1800-0000-e794-bd36e40b0000 pid=3044 execve guuid=4b86e7e9-1800-0000-e794-bd36e50b0000 pid=3045 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=4b86e7e9-1800-0000-e794-bd36e50b0000 pid=3045 execve guuid=c2684eea-1800-0000-e794-bd36e60b0000 pid=3046 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=c2684eea-1800-0000-e794-bd36e60b0000 pid=3046 execve guuid=5268afea-1800-0000-e794-bd36e70b0000 pid=3047 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=5268afea-1800-0000-e794-bd36e70b0000 pid=3047 execve guuid=34700aeb-1800-0000-e794-bd36e80b0000 pid=3048 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=34700aeb-1800-0000-e794-bd36e80b0000 pid=3048 execve guuid=963769eb-1800-0000-e794-bd36e90b0000 pid=3049 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=963769eb-1800-0000-e794-bd36e90b0000 pid=3049 execve guuid=b636cceb-1800-0000-e794-bd36ea0b0000 pid=3050 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=b636cceb-1800-0000-e794-bd36ea0b0000 pid=3050 execve guuid=9bd528ec-1800-0000-e794-bd36eb0b0000 pid=3051 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=9bd528ec-1800-0000-e794-bd36eb0b0000 pid=3051 execve guuid=ecd374ec-1800-0000-e794-bd36ec0b0000 pid=3052 /usr/bin/mkdir guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=ecd374ec-1800-0000-e794-bd36ec0b0000 pid=3052 execve guuid=2b15c8ec-1800-0000-e794-bd36ed0b0000 pid=3053 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=2b15c8ec-1800-0000-e794-bd36ed0b0000 pid=3053 execve guuid=193352ed-1800-0000-e794-bd36ee0b0000 pid=3054 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=193352ed-1800-0000-e794-bd36ee0b0000 pid=3054 execve guuid=fa26a7ee-1800-0000-e794-bd36ef0b0000 pid=3055 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=fa26a7ee-1800-0000-e794-bd36ef0b0000 pid=3055 execve guuid=8bdc3fef-1800-0000-e794-bd36f00b0000 pid=3056 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=8bdc3fef-1800-0000-e794-bd36f00b0000 pid=3056 execve guuid=eef1d2ef-1800-0000-e794-bd36f10b0000 pid=3057 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=eef1d2ef-1800-0000-e794-bd36f10b0000 pid=3057 execve guuid=20645ff0-1800-0000-e794-bd36f20b0000 pid=3058 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=20645ff0-1800-0000-e794-bd36f20b0000 pid=3058 execve guuid=3db1edf0-1800-0000-e794-bd36f30b0000 pid=3059 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=3db1edf0-1800-0000-e794-bd36f30b0000 pid=3059 execve guuid=b73970f1-1800-0000-e794-bd36f40b0000 pid=3060 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=b73970f1-1800-0000-e794-bd36f40b0000 pid=3060 execve guuid=d4f2f8f1-1800-0000-e794-bd36f50b0000 pid=3061 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=d4f2f8f1-1800-0000-e794-bd36f50b0000 pid=3061 execve guuid=83ec81f2-1800-0000-e794-bd36f60b0000 pid=3062 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=83ec81f2-1800-0000-e794-bd36f60b0000 pid=3062 execve guuid=abd307f3-1800-0000-e794-bd36f70b0000 pid=3063 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=abd307f3-1800-0000-e794-bd36f70b0000 pid=3063 execve guuid=63577cf3-1800-0000-e794-bd36f80b0000 pid=3064 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=63577cf3-1800-0000-e794-bd36f80b0000 pid=3064 execve guuid=48f7f7f3-1800-0000-e794-bd36f90b0000 pid=3065 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=48f7f7f3-1800-0000-e794-bd36f90b0000 pid=3065 execve guuid=dbfa8ff4-1800-0000-e794-bd36fa0b0000 pid=3066 /usr/bin/cp guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=dbfa8ff4-1800-0000-e794-bd36fa0b0000 pid=3066 execve guuid=610121f5-1800-0000-e794-bd36fb0b0000 pid=3067 /usr/bin/touch guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=610121f5-1800-0000-e794-bd36fb0b0000 pid=3067 execve guuid=f8c598f5-1800-0000-e794-bd36fc0b0000 pid=3068 /usr/bin/chmod guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=f8c598f5-1800-0000-e794-bd36fc0b0000 pid=3068 execve guuid=1130ecf5-1800-0000-e794-bd36fd0b0000 pid=3069 /usr/bin/chmod guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=1130ecf5-1800-0000-e794-bd36fd0b0000 pid=3069 execve guuid=03073cf6-1800-0000-e794-bd36fe0b0000 pid=3070 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=03073cf6-1800-0000-e794-bd36fe0b0000 pid=3070 execve guuid=ea6aa9f6-1800-0000-e794-bd36ff0b0000 pid=3071 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=ea6aa9f6-1800-0000-e794-bd36ff0b0000 pid=3071 execve guuid=1709faf6-1800-0000-e794-bd36000c0000 pid=3072 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=1709faf6-1800-0000-e794-bd36000c0000 pid=3072 execve guuid=a2e963f7-1800-0000-e794-bd36010c0000 pid=3073 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=a2e963f7-1800-0000-e794-bd36010c0000 pid=3073 execve guuid=ba64d6f7-1800-0000-e794-bd36020c0000 pid=3074 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=ba64d6f7-1800-0000-e794-bd36020c0000 pid=3074 execve guuid=cef551f8-1800-0000-e794-bd36030c0000 pid=3075 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=cef551f8-1800-0000-e794-bd36030c0000 pid=3075 execve guuid=19dac5f8-1800-0000-e794-bd36040c0000 pid=3076 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=19dac5f8-1800-0000-e794-bd36040c0000 pid=3076 execve guuid=371d16f9-1800-0000-e794-bd36050c0000 pid=3077 /usr/bin/chattr guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=371d16f9-1800-0000-e794-bd36050c0000 pid=3077 execve guuid=a73a66f9-1800-0000-e794-bd36060c0000 pid=3078 /usr/bin/bash guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=a73a66f9-1800-0000-e794-bd36060c0000 pid=3078 clone guuid=f0206ef9-1800-0000-e794-bd36070c0000 pid=3079 /usr/bin/bash guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=f0206ef9-1800-0000-e794-bd36070c0000 pid=3079 clone guuid=2f54c4f9-1800-0000-e794-bd36080c0000 pid=3080 /usr/bin/curl net guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=2f54c4f9-1800-0000-e794-bd36080c0000 pid=3080 execve guuid=0116ccf9-1800-0000-e794-bd36090c0000 pid=3081 /usr/bin/dash guuid=06ccc0e7-1800-0000-e794-bd36df0b0000 pid=3039->guuid=0116ccf9-1800-0000-e794-bd36090c0000 pid=3081 execve 124ee36c-bdbd-5d46-bbb1-b2cd81367f04 160.119.69.4:80 guuid=2f54c4f9-1800-0000-e794-bd36080c0000 pid=3080->124ee36c-bdbd-5d46-bbb1-b2cd81367f04 con
Threat name:
Linux.Backdoor.WebShell
Status:
Malicious
First seen:
2026-07-24 07:23:02 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 01d44bd0e993541e1182882a4fa010de1b7ae9dbb38dd8ab10ff63c5b9889115

(this sample)

  
Delivery method
Distributed via web download

Comments