MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02cd1f9777760d4f9efd5fb77bb356e056c375ab2dc09446db76437243627406. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 02cd1f9777760d4f9efd5fb77bb356e056c375ab2dc09446db76437243627406
SHA3-384 hash: ae1eb9af1866e63f4015503d73f8de03f768703a8c04311addf674810ab93bf947e9f096e575aae25bea29eb54025bd1
SHA1 hash: 5b5766b7c766c2fa634c5a85f5b0d91be8a5e20a
MD5 hash: 926fef929129191415637ac174ebe093
humanhash: alpha-william-lactose-south
File name:kla.sh
Download: download sample
File size:3'451 bytes
First seen:2026-02-22 16:51:39 UTC
Last seen:2026-02-22 19:40:27 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:1RGXNLwhWUNDwdkHE3/3EDfkHE3/3tGdDQkHE3/3PQDnwkHE3/3qLDFkHE3/34DH:1IvakVklgkekTkgk4kW4kq/kPkIX
TLSH T12A61E7E5A2381D2A75CA8D48F555D1911CDBBB32BFFA60C0D0C2EDB15EA97082E18F71
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=33e55eee-1800-0000-7397-0de5050b0000 pid=2821 /usr/bin/sudo guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825 /tmp/sample.bin guuid=33e55eee-1800-0000-7397-0de5050b0000 pid=2821->guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825 execve guuid=30acfcf0-1800-0000-7397-0de50b0b0000 pid=2827 /usr/bin/rm guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=30acfcf0-1800-0000-7397-0de50b0b0000 pid=2827 execve guuid=e96f82f1-1800-0000-7397-0de50e0b0000 pid=2830 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=e96f82f1-1800-0000-7397-0de50e0b0000 pid=2830 execve guuid=df8fd8fa-1800-0000-7397-0de5220b0000 pid=2850 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=df8fd8fa-1800-0000-7397-0de5220b0000 pid=2850 execve guuid=9f0cc006-1900-0000-7397-0de5400b0000 pid=2880 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=9f0cc006-1900-0000-7397-0de5400b0000 pid=2880 execve guuid=40732d0d-1900-0000-7397-0de5540b0000 pid=2900 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=40732d0d-1900-0000-7397-0de5540b0000 pid=2900 execve guuid=a11ecc16-1900-0000-7397-0de5680b0000 pid=2920 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=a11ecc16-1900-0000-7397-0de5680b0000 pid=2920 execve guuid=ed5b0c1e-1900-0000-7397-0de56d0b0000 pid=2925 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=ed5b0c1e-1900-0000-7397-0de56d0b0000 pid=2925 execve guuid=e7e11d27-1900-0000-7397-0de57c0b0000 pid=2940 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=e7e11d27-1900-0000-7397-0de57c0b0000 pid=2940 execve guuid=fb681e2e-1900-0000-7397-0de58b0b0000 pid=2955 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=fb681e2e-1900-0000-7397-0de58b0b0000 pid=2955 execve guuid=5c432636-1900-0000-7397-0de59e0b0000 pid=2974 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=5c432636-1900-0000-7397-0de59e0b0000 pid=2974 execve guuid=4c94bd3c-1900-0000-7397-0de5ac0b0000 pid=2988 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=4c94bd3c-1900-0000-7397-0de5ac0b0000 pid=2988 execve guuid=7c644e44-1900-0000-7397-0de5c00b0000 pid=3008 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=7c644e44-1900-0000-7397-0de5c00b0000 pid=3008 execve guuid=6a24664b-1900-0000-7397-0de5d00b0000 pid=3024 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=6a24664b-1900-0000-7397-0de5d00b0000 pid=3024 execve guuid=a78fcf53-1900-0000-7397-0de5e80b0000 pid=3048 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=a78fcf53-1900-0000-7397-0de5e80b0000 pid=3048 execve guuid=63edd75a-1900-0000-7397-0de5fb0b0000 pid=3067 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=63edd75a-1900-0000-7397-0de5fb0b0000 pid=3067 execve guuid=9d2d4563-1900-0000-7397-0de50a0c0000 pid=3082 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=9d2d4563-1900-0000-7397-0de50a0c0000 pid=3082 execve guuid=3567b46a-1900-0000-7397-0de51f0c0000 pid=3103 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=3567b46a-1900-0000-7397-0de51f0c0000 pid=3103 execve guuid=93078b73-1900-0000-7397-0de5340c0000 pid=3124 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=93078b73-1900-0000-7397-0de5340c0000 pid=3124 execve guuid=4db3bb7a-1900-0000-7397-0de54c0c0000 pid=3148 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=4db3bb7a-1900-0000-7397-0de54c0c0000 pid=3148 execve guuid=35cac882-1900-0000-7397-0de5610c0000 pid=3169 /usr/bin/wget net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=35cac882-1900-0000-7397-0de5610c0000 pid=3169 execve guuid=231bed89-1900-0000-7397-0de5710c0000 pid=3185 /usr/bin/curl net send-data guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=231bed89-1900-0000-7397-0de5710c0000 pid=3185 execve guuid=df6fe894-1900-0000-7397-0de57c0c0000 pid=3196 /usr/bin/sleep guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=df6fe894-1900-0000-7397-0de57c0c0000 pid=3196 execve guuid=32df6c48-1a00-0000-7397-0de5c40d0000 pid=3524 /usr/bin/rm delete-file guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=32df6c48-1a00-0000-7397-0de5c40d0000 pid=3524 execve guuid=3f2ed948-1a00-0000-7397-0de5c60d0000 pid=3526 /usr/bin/pgrep guuid=58b794f0-1800-0000-7397-0de5090b0000 pid=2825->guuid=3f2ed948-1a00-0000-7397-0de5c60d0000 pid=3526 execve 6195e6b5-e3c6-5f01-a515-05dca5a8217a 91.92.241.159:80 guuid=e96f82f1-1800-0000-7397-0de50e0b0000 pid=2830->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 136B guuid=df8fd8fa-1800-0000-7397-0de5220b0000 pid=2850->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 85B guuid=9f0cc006-1900-0000-7397-0de5400b0000 pid=2880->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=40732d0d-1900-0000-7397-0de5540b0000 pid=2900->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=a11ecc16-1900-0000-7397-0de5680b0000 pid=2920->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=ed5b0c1e-1900-0000-7397-0de56d0b0000 pid=2925->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=e7e11d27-1900-0000-7397-0de57c0b0000 pid=2940->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=fb681e2e-1900-0000-7397-0de58b0b0000 pid=2955->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=5c432636-1900-0000-7397-0de59e0b0000 pid=2974->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=4c94bd3c-1900-0000-7397-0de5ac0b0000 pid=2988->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=7c644e44-1900-0000-7397-0de5c00b0000 pid=3008->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=6a24664b-1900-0000-7397-0de5d00b0000 pid=3024->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=a78fcf53-1900-0000-7397-0de5e80b0000 pid=3048->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=63edd75a-1900-0000-7397-0de5fb0b0000 pid=3067->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=9d2d4563-1900-0000-7397-0de50a0c0000 pid=3082->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 136B guuid=3567b46a-1900-0000-7397-0de51f0c0000 pid=3103->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 85B guuid=93078b73-1900-0000-7397-0de5340c0000 pid=3124->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 137B guuid=4db3bb7a-1900-0000-7397-0de54c0c0000 pid=3148->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 86B guuid=35cac882-1900-0000-7397-0de5610c0000 pid=3169->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 136B guuid=231bed89-1900-0000-7397-0de5710c0000 pid=3185->6195e6b5-e3c6-5f01-a515-05dca5a8217a send: 85B
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Checks CPU configuration
Reads CPU attributes
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 02cd1f9777760d4f9efd5fb77bb356e056c375ab2dc09446db76437243627406

(this sample)

  
Delivery method
Distributed via web download

Comments