MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0bc73f1b515e2352c9c10159c8be2d7927f15291106ddb516eaaa3bf91e1b5d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 0bc73f1b515e2352c9c10159c8be2d7927f15291106ddb516eaaa3bf91e1b5d5
SHA3-384 hash: 2e47ec6e69f067840f53a37cc926180e6b614e1128d3b97a9b75d3be8190810b7af67f210c406124ee232896dad59018
SHA1 hash: 045858f0316045e058000159f0b381ddbf6fece3
MD5 hash: f9be0e12626e128332c9c6ab25bfb2ff
humanhash: music-king-twelve-six
File name:lil
Download: download sample
File size:843 bytes
First seen:2026-06-03 14:09:40 UTC
Last seen:2026-06-04 08:43:27 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaMD+wzQJNj/qfci1RYX:e9Qp+MsMa8QPSUi1RYX
TLSH T1EC01AFCDC41A971041D5F89D36972545B410C3CF294ACB68FE6C547D8BAEA5C7065FC8
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/ZVGzn/an/aelf ua-wget
http://188.132.232.81/zVyn/an/aelf ua-wget
http://188.132.232.81/Ca9kn/an/aelf ua-wget
http://188.132.232.81/0xFnn/an/aelf ua-wget
http://188.132.232.81/TROn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-03T11:22:00Z UTC
Last seen:
2026-06-04T00:01:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4b6d8eb2-1a00-0000-c59c-b4152f0a0000 pid=2607 /usr/bin/sudo guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614 /tmp/sample.bin write-file guuid=4b6d8eb2-1a00-0000-c59c-b4152f0a0000 pid=2607->guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614 execve guuid=a93828b5-1a00-0000-c59c-b415390a0000 pid=2617 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a93828b5-1a00-0000-c59c-b415390a0000 pid=2617 execve guuid=f34ac5b5-1a00-0000-c59c-b4153b0a0000 pid=2619 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f34ac5b5-1a00-0000-c59c-b4153b0a0000 pid=2619 execve guuid=8fa037b6-1a00-0000-c59c-b4153d0a0000 pid=2621 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8fa037b6-1a00-0000-c59c-b4153d0a0000 pid=2621 execve guuid=9487a5b6-1a00-0000-c59c-b415400a0000 pid=2624 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=9487a5b6-1a00-0000-c59c-b415400a0000 pid=2624 execve guuid=535334b7-1a00-0000-c59c-b415420a0000 pid=2626 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=535334b7-1a00-0000-c59c-b415420a0000 pid=2626 execve guuid=9f1298b7-1a00-0000-c59c-b415450a0000 pid=2629 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=9f1298b7-1a00-0000-c59c-b415450a0000 pid=2629 execve guuid=43ebf9b7-1a00-0000-c59c-b415470a0000 pid=2631 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=43ebf9b7-1a00-0000-c59c-b415470a0000 pid=2631 execve guuid=67887bb8-1a00-0000-c59c-b415490a0000 pid=2633 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=67887bb8-1a00-0000-c59c-b415490a0000 pid=2633 execve guuid=a499e7b8-1a00-0000-c59c-b4154c0a0000 pid=2636 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a499e7b8-1a00-0000-c59c-b4154c0a0000 pid=2636 execve guuid=f1d959b9-1a00-0000-c59c-b4154e0a0000 pid=2638 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f1d959b9-1a00-0000-c59c-b4154e0a0000 pid=2638 execve guuid=2507cab9-1a00-0000-c59c-b415510a0000 pid=2641 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=2507cab9-1a00-0000-c59c-b415510a0000 pid=2641 execve guuid=5fef45ba-1a00-0000-c59c-b415530a0000 pid=2643 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=5fef45ba-1a00-0000-c59c-b415530a0000 pid=2643 execve guuid=b43bbaba-1a00-0000-c59c-b415550a0000 pid=2645 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=b43bbaba-1a00-0000-c59c-b415550a0000 pid=2645 execve guuid=f57352bb-1a00-0000-c59c-b415580a0000 pid=2648 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f57352bb-1a00-0000-c59c-b415580a0000 pid=2648 execve guuid=ea8de2bb-1a00-0000-c59c-b4155a0a0000 pid=2650 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ea8de2bb-1a00-0000-c59c-b4155a0a0000 pid=2650 execve guuid=f2de6cbc-1a00-0000-c59c-b4155d0a0000 pid=2653 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f2de6cbc-1a00-0000-c59c-b4155d0a0000 pid=2653 execve guuid=c70419bd-1a00-0000-c59c-b415600a0000 pid=2656 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=c70419bd-1a00-0000-c59c-b415600a0000 pid=2656 execve guuid=43e087bd-1a00-0000-c59c-b415620a0000 pid=2658 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=43e087bd-1a00-0000-c59c-b415620a0000 pid=2658 execve guuid=cbc5fabd-1a00-0000-c59c-b415640a0000 pid=2660 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=cbc5fabd-1a00-0000-c59c-b415640a0000 pid=2660 execve guuid=e62283be-1a00-0000-c59c-b415660a0000 pid=2662 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e62283be-1a00-0000-c59c-b415660a0000 pid=2662 execve guuid=63a502bf-1a00-0000-c59c-b415690a0000 pid=2665 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=63a502bf-1a00-0000-c59c-b415690a0000 pid=2665 execve guuid=47ee80bf-1a00-0000-c59c-b4156b0a0000 pid=2667 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=47ee80bf-1a00-0000-c59c-b4156b0a0000 pid=2667 execve guuid=024ee9bf-1a00-0000-c59c-b4156e0a0000 pid=2670 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=024ee9bf-1a00-0000-c59c-b4156e0a0000 pid=2670 execve guuid=eaac49c0-1a00-0000-c59c-b415700a0000 pid=2672 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=eaac49c0-1a00-0000-c59c-b415700a0000 pid=2672 execve guuid=a6abaec0-1a00-0000-c59c-b415720a0000 pid=2674 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a6abaec0-1a00-0000-c59c-b415720a0000 pid=2674 execve guuid=098d13c1-1a00-0000-c59c-b415740a0000 pid=2676 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=098d13c1-1a00-0000-c59c-b415740a0000 pid=2676 execve guuid=2ffd82c1-1a00-0000-c59c-b415770a0000 pid=2679 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=2ffd82c1-1a00-0000-c59c-b415770a0000 pid=2679 execve guuid=39f4ebc1-1a00-0000-c59c-b415790a0000 pid=2681 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=39f4ebc1-1a00-0000-c59c-b415790a0000 pid=2681 execve guuid=125760c2-1a00-0000-c59c-b4157c0a0000 pid=2684 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=125760c2-1a00-0000-c59c-b4157c0a0000 pid=2684 execve guuid=805bebc2-1a00-0000-c59c-b4157e0a0000 pid=2686 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=805bebc2-1a00-0000-c59c-b4157e0a0000 pid=2686 execve guuid=941f5ac3-1a00-0000-c59c-b415810a0000 pid=2689 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=941f5ac3-1a00-0000-c59c-b415810a0000 pid=2689 execve guuid=21cec4c3-1a00-0000-c59c-b415830a0000 pid=2691 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=21cec4c3-1a00-0000-c59c-b415830a0000 pid=2691 execve guuid=6bbd36c4-1a00-0000-c59c-b415850a0000 pid=2693 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=6bbd36c4-1a00-0000-c59c-b415850a0000 pid=2693 execve guuid=e104a9c4-1a00-0000-c59c-b415870a0000 pid=2695 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e104a9c4-1a00-0000-c59c-b415870a0000 pid=2695 execve guuid=499119c5-1a00-0000-c59c-b4158a0a0000 pid=2698 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=499119c5-1a00-0000-c59c-b4158a0a0000 pid=2698 execve guuid=a657e9c5-1a00-0000-c59c-b4158d0a0000 pid=2701 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a657e9c5-1a00-0000-c59c-b4158d0a0000 pid=2701 execve guuid=5e4276c6-1a00-0000-c59c-b4158f0a0000 pid=2703 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=5e4276c6-1a00-0000-c59c-b4158f0a0000 pid=2703 execve guuid=fad8e2c6-1a00-0000-c59c-b415910a0000 pid=2705 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=fad8e2c6-1a00-0000-c59c-b415910a0000 pid=2705 execve guuid=44364ac7-1a00-0000-c59c-b415940a0000 pid=2708 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=44364ac7-1a00-0000-c59c-b415940a0000 pid=2708 execve guuid=dccfe1c7-1a00-0000-c59c-b415970a0000 pid=2711 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=dccfe1c7-1a00-0000-c59c-b415970a0000 pid=2711 execve guuid=99eb48c8-1a00-0000-c59c-b415990a0000 pid=2713 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=99eb48c8-1a00-0000-c59c-b415990a0000 pid=2713 execve guuid=9197d6c8-1a00-0000-c59c-b4159c0a0000 pid=2716 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=9197d6c8-1a00-0000-c59c-b4159c0a0000 pid=2716 execve guuid=30633ac9-1a00-0000-c59c-b4159e0a0000 pid=2718 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=30633ac9-1a00-0000-c59c-b4159e0a0000 pid=2718 execve guuid=85d5c3c9-1a00-0000-c59c-b415a10a0000 pid=2721 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=85d5c3c9-1a00-0000-c59c-b415a10a0000 pid=2721 execve guuid=905a2cca-1a00-0000-c59c-b415a30a0000 pid=2723 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=905a2cca-1a00-0000-c59c-b415a30a0000 pid=2723 execve guuid=f4e5bdca-1a00-0000-c59c-b415a60a0000 pid=2726 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f4e5bdca-1a00-0000-c59c-b415a60a0000 pid=2726 execve guuid=35e438cb-1a00-0000-c59c-b415a80a0000 pid=2728 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=35e438cb-1a00-0000-c59c-b415a80a0000 pid=2728 execve guuid=fed8abcb-1a00-0000-c59c-b415ab0a0000 pid=2731 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=fed8abcb-1a00-0000-c59c-b415ab0a0000 pid=2731 execve guuid=37a725cc-1a00-0000-c59c-b415ae0a0000 pid=2734 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=37a725cc-1a00-0000-c59c-b415ae0a0000 pid=2734 execve guuid=2c70d6cc-1a00-0000-c59c-b415af0a0000 pid=2735 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=2c70d6cc-1a00-0000-c59c-b415af0a0000 pid=2735 execve guuid=ca626ccd-1a00-0000-c59c-b415b20a0000 pid=2738 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ca626ccd-1a00-0000-c59c-b415b20a0000 pid=2738 execve guuid=141601ce-1a00-0000-c59c-b415b40a0000 pid=2740 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=141601ce-1a00-0000-c59c-b415b40a0000 pid=2740 execve guuid=8e2d9ece-1a00-0000-c59c-b415b60a0000 pid=2742 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8e2d9ece-1a00-0000-c59c-b415b60a0000 pid=2742 execve guuid=cec535cf-1a00-0000-c59c-b415b90a0000 pid=2745 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=cec535cf-1a00-0000-c59c-b415b90a0000 pid=2745 execve guuid=1b45b8cf-1a00-0000-c59c-b415bc0a0000 pid=2748 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=1b45b8cf-1a00-0000-c59c-b415bc0a0000 pid=2748 execve guuid=a78d49d0-1a00-0000-c59c-b415bf0a0000 pid=2751 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a78d49d0-1a00-0000-c59c-b415bf0a0000 pid=2751 execve guuid=88efdbd0-1a00-0000-c59c-b415c10a0000 pid=2753 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=88efdbd0-1a00-0000-c59c-b415c10a0000 pid=2753 execve guuid=a09a64d1-1a00-0000-c59c-b415c40a0000 pid=2756 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a09a64d1-1a00-0000-c59c-b415c40a0000 pid=2756 execve guuid=b0acffd1-1a00-0000-c59c-b415c60a0000 pid=2758 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=b0acffd1-1a00-0000-c59c-b415c60a0000 pid=2758 execve guuid=e26790d2-1a00-0000-c59c-b415c90a0000 pid=2761 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e26790d2-1a00-0000-c59c-b415c90a0000 pid=2761 execve guuid=a15921d3-1a00-0000-c59c-b415cc0a0000 pid=2764 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a15921d3-1a00-0000-c59c-b415cc0a0000 pid=2764 execve guuid=3db8b9d3-1a00-0000-c59c-b415cf0a0000 pid=2767 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=3db8b9d3-1a00-0000-c59c-b415cf0a0000 pid=2767 execve guuid=21c629d4-1a00-0000-c59c-b415d10a0000 pid=2769 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=21c629d4-1a00-0000-c59c-b415d10a0000 pid=2769 execve guuid=561e94d4-1a00-0000-c59c-b415d30a0000 pid=2771 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=561e94d4-1a00-0000-c59c-b415d30a0000 pid=2771 execve guuid=ce8d00d5-1a00-0000-c59c-b415d50a0000 pid=2773 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ce8d00d5-1a00-0000-c59c-b415d50a0000 pid=2773 execve guuid=97ded7d5-1a00-0000-c59c-b415d80a0000 pid=2776 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=97ded7d5-1a00-0000-c59c-b415d80a0000 pid=2776 execve guuid=7020a5d6-1a00-0000-c59c-b415dc0a0000 pid=2780 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=7020a5d6-1a00-0000-c59c-b415dc0a0000 pid=2780 execve guuid=d9391ed7-1a00-0000-c59c-b415de0a0000 pid=2782 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=d9391ed7-1a00-0000-c59c-b415de0a0000 pid=2782 execve guuid=1f2db9d7-1a00-0000-c59c-b415e10a0000 pid=2785 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=1f2db9d7-1a00-0000-c59c-b415e10a0000 pid=2785 execve guuid=8e2c25d8-1a00-0000-c59c-b415e30a0000 pid=2787 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8e2c25d8-1a00-0000-c59c-b415e30a0000 pid=2787 execve guuid=108cb3d8-1a00-0000-c59c-b415e60a0000 pid=2790 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=108cb3d8-1a00-0000-c59c-b415e60a0000 pid=2790 execve guuid=4b3248d9-1a00-0000-c59c-b415e80a0000 pid=2792 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=4b3248d9-1a00-0000-c59c-b415e80a0000 pid=2792 execve guuid=379dbed9-1a00-0000-c59c-b415eb0a0000 pid=2795 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=379dbed9-1a00-0000-c59c-b415eb0a0000 pid=2795 execve guuid=e2a334da-1a00-0000-c59c-b415ed0a0000 pid=2797 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e2a334da-1a00-0000-c59c-b415ed0a0000 pid=2797 execve guuid=896cc5da-1a00-0000-c59c-b415ef0a0000 pid=2799 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=896cc5da-1a00-0000-c59c-b415ef0a0000 pid=2799 execve guuid=39775fdb-1a00-0000-c59c-b415f20a0000 pid=2802 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=39775fdb-1a00-0000-c59c-b415f20a0000 pid=2802 execve guuid=0fc613dc-1a00-0000-c59c-b415f40a0000 pid=2804 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=0fc613dc-1a00-0000-c59c-b415f40a0000 pid=2804 execve guuid=6fd281dc-1a00-0000-c59c-b415f60a0000 pid=2806 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=6fd281dc-1a00-0000-c59c-b415f60a0000 pid=2806 execve guuid=c4c80cdd-1a00-0000-c59c-b415f90a0000 pid=2809 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=c4c80cdd-1a00-0000-c59c-b415f90a0000 pid=2809 execve guuid=b34886dd-1a00-0000-c59c-b415fb0a0000 pid=2811 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=b34886dd-1a00-0000-c59c-b415fb0a0000 pid=2811 execve guuid=8bec11de-1a00-0000-c59c-b415fd0a0000 pid=2813 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8bec11de-1a00-0000-c59c-b415fd0a0000 pid=2813 execve guuid=9bc28fde-1a00-0000-c59c-b415010b0000 pid=2817 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=9bc28fde-1a00-0000-c59c-b415010b0000 pid=2817 execve guuid=c82f14df-1a00-0000-c59c-b415020b0000 pid=2818 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=c82f14df-1a00-0000-c59c-b415020b0000 pid=2818 execve guuid=29ec8edf-1a00-0000-c59c-b415030b0000 pid=2819 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=29ec8edf-1a00-0000-c59c-b415030b0000 pid=2819 execve guuid=a5de72e0-1a00-0000-c59c-b415060b0000 pid=2822 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=a5de72e0-1a00-0000-c59c-b415060b0000 pid=2822 execve guuid=cb8a02e1-1a00-0000-c59c-b415090b0000 pid=2825 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=cb8a02e1-1a00-0000-c59c-b415090b0000 pid=2825 execve guuid=78c59ee1-1a00-0000-c59c-b4150c0b0000 pid=2828 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=78c59ee1-1a00-0000-c59c-b4150c0b0000 pid=2828 execve guuid=d0711be2-1a00-0000-c59c-b4150f0b0000 pid=2831 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=d0711be2-1a00-0000-c59c-b4150f0b0000 pid=2831 execve guuid=4c57f9e2-1a00-0000-c59c-b415120b0000 pid=2834 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=4c57f9e2-1a00-0000-c59c-b415120b0000 pid=2834 execve guuid=3ce896e3-1a00-0000-c59c-b415140b0000 pid=2836 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=3ce896e3-1a00-0000-c59c-b415140b0000 pid=2836 execve guuid=06e02de4-1a00-0000-c59c-b415150b0000 pid=2837 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=06e02de4-1a00-0000-c59c-b415150b0000 pid=2837 execve guuid=e80ea0e4-1a00-0000-c59c-b415170b0000 pid=2839 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e80ea0e4-1a00-0000-c59c-b415170b0000 pid=2839 execve guuid=783c17e5-1a00-0000-c59c-b4151a0b0000 pid=2842 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=783c17e5-1a00-0000-c59c-b4151a0b0000 pid=2842 execve guuid=9dbcf7e5-1a00-0000-c59c-b4151d0b0000 pid=2845 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=9dbcf7e5-1a00-0000-c59c-b4151d0b0000 pid=2845 execve guuid=2eaee3e6-1a00-0000-c59c-b415200b0000 pid=2848 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=2eaee3e6-1a00-0000-c59c-b415200b0000 pid=2848 execve guuid=1da592e7-1a00-0000-c59c-b415220b0000 pid=2850 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=1da592e7-1a00-0000-c59c-b415220b0000 pid=2850 execve guuid=c46e04e8-1a00-0000-c59c-b415240b0000 pid=2852 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=c46e04e8-1a00-0000-c59c-b415240b0000 pid=2852 execve guuid=be396ae8-1a00-0000-c59c-b415260b0000 pid=2854 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=be396ae8-1a00-0000-c59c-b415260b0000 pid=2854 execve guuid=ebfec9e8-1a00-0000-c59c-b415290b0000 pid=2857 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ebfec9e8-1a00-0000-c59c-b415290b0000 pid=2857 execve guuid=ada15ce9-1a00-0000-c59c-b4152b0b0000 pid=2859 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ada15ce9-1a00-0000-c59c-b4152b0b0000 pid=2859 execve guuid=e3231cea-1a00-0000-c59c-b4152d0b0000 pid=2861 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e3231cea-1a00-0000-c59c-b4152d0b0000 pid=2861 execve guuid=276e84ea-1a00-0000-c59c-b4152e0b0000 pid=2862 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=276e84ea-1a00-0000-c59c-b4152e0b0000 pid=2862 execve guuid=eaebeeea-1a00-0000-c59c-b4152f0b0000 pid=2863 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=eaebeeea-1a00-0000-c59c-b4152f0b0000 pid=2863 execve guuid=138f4aeb-1a00-0000-c59c-b415310b0000 pid=2865 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=138f4aeb-1a00-0000-c59c-b415310b0000 pid=2865 execve guuid=6b30a8eb-1a00-0000-c59c-b415330b0000 pid=2867 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=6b30a8eb-1a00-0000-c59c-b415330b0000 pid=2867 execve guuid=8f740aec-1a00-0000-c59c-b415350b0000 pid=2869 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8f740aec-1a00-0000-c59c-b415350b0000 pid=2869 execve guuid=f34f66ec-1a00-0000-c59c-b415380b0000 pid=2872 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f34f66ec-1a00-0000-c59c-b415380b0000 pid=2872 execve guuid=e203d3ec-1a00-0000-c59c-b4153a0b0000 pid=2874 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e203d3ec-1a00-0000-c59c-b4153a0b0000 pid=2874 execve guuid=8c4586ed-1a00-0000-c59c-b4153b0b0000 pid=2875 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8c4586ed-1a00-0000-c59c-b4153b0b0000 pid=2875 execve guuid=35674cee-1a00-0000-c59c-b4153c0b0000 pid=2876 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=35674cee-1a00-0000-c59c-b4153c0b0000 pid=2876 execve guuid=8f7006ef-1a00-0000-c59c-b4153d0b0000 pid=2877 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=8f7006ef-1a00-0000-c59c-b4153d0b0000 pid=2877 execve guuid=cb06e1ef-1a00-0000-c59c-b4153e0b0000 pid=2878 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=cb06e1ef-1a00-0000-c59c-b4153e0b0000 pid=2878 execve guuid=29c675f0-1a00-0000-c59c-b4153f0b0000 pid=2879 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=29c675f0-1a00-0000-c59c-b4153f0b0000 pid=2879 execve guuid=e63327f1-1a00-0000-c59c-b415400b0000 pid=2880 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=e63327f1-1a00-0000-c59c-b415400b0000 pid=2880 execve guuid=2cbcd2f1-1a00-0000-c59c-b415410b0000 pid=2881 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=2cbcd2f1-1a00-0000-c59c-b415410b0000 pid=2881 execve guuid=3e64abf2-1a00-0000-c59c-b415420b0000 pid=2882 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=3e64abf2-1a00-0000-c59c-b415420b0000 pid=2882 execve guuid=d85b30f3-1a00-0000-c59c-b415440b0000 pid=2884 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=d85b30f3-1a00-0000-c59c-b415440b0000 pid=2884 execve guuid=026fdbf3-1a00-0000-c59c-b415450b0000 pid=2885 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=026fdbf3-1a00-0000-c59c-b415450b0000 pid=2885 execve guuid=aa35a6f4-1a00-0000-c59c-b415460b0000 pid=2886 /usr/bin/ls guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=aa35a6f4-1a00-0000-c59c-b415460b0000 pid=2886 execve guuid=d0f827f5-1a00-0000-c59c-b415470b0000 pid=2887 /usr/bin/rm guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=d0f827f5-1a00-0000-c59c-b415470b0000 pid=2887 execve guuid=0f8086f5-1a00-0000-c59c-b415490b0000 pid=2889 /usr/bin/wget net send-data write-file guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=0f8086f5-1a00-0000-c59c-b415490b0000 pid=2889 execve guuid=6e492e47-1b00-0000-c59c-b415d20b0000 pid=3026 /usr/bin/chmod guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=6e492e47-1b00-0000-c59c-b415d20b0000 pid=3026 execve guuid=22f8e647-1b00-0000-c59c-b415d50b0000 pid=3029 /usr/bin/dash guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=22f8e647-1b00-0000-c59c-b415d50b0000 pid=3029 clone guuid=0543cc48-1b00-0000-c59c-b415d80b0000 pid=3032 /usr/bin/rm guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=0543cc48-1b00-0000-c59c-b415d80b0000 pid=3032 execve guuid=5a5c2649-1b00-0000-c59c-b415da0b0000 pid=3034 /usr/bin/wget net send-data write-file guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=5a5c2649-1b00-0000-c59c-b415da0b0000 pid=3034 execve guuid=ebfa7d3a-1d00-0000-c59c-b415760f0000 pid=3958 /usr/bin/chmod guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ebfa7d3a-1d00-0000-c59c-b415760f0000 pid=3958 execve guuid=f6efe23a-1d00-0000-c59c-b415780f0000 pid=3960 /usr/bin/dash guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f6efe23a-1d00-0000-c59c-b415780f0000 pid=3960 clone guuid=f3c2653c-1d00-0000-c59c-b4157d0f0000 pid=3965 /usr/bin/rm guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=f3c2653c-1d00-0000-c59c-b4157d0f0000 pid=3965 execve guuid=2bf5d63c-1d00-0000-c59c-b415800f0000 pid=3968 /usr/bin/wget net send-data write-file guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=2bf5d63c-1d00-0000-c59c-b415800f0000 pid=3968 execve guuid=1345759a-1d00-0000-c59c-b4158c100000 pid=4236 /usr/bin/chmod guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=1345759a-1d00-0000-c59c-b4158c100000 pid=4236 execve guuid=aaa2e89a-1d00-0000-c59c-b4158d100000 pid=4237 /usr/bin/dash guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=aaa2e89a-1d00-0000-c59c-b4158d100000 pid=4237 clone guuid=fcd2089c-1d00-0000-c59c-b41593100000 pid=4243 /usr/bin/rm guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=fcd2089c-1d00-0000-c59c-b41593100000 pid=4243 execve guuid=d756ad9c-1d00-0000-c59c-b41596100000 pid=4246 /usr/bin/wget net send-data write-file guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=d756ad9c-1d00-0000-c59c-b41596100000 pid=4246 execve guuid=66a3fcab-1e00-0000-c59c-b415ae130000 pid=5038 /usr/bin/chmod guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=66a3fcab-1e00-0000-c59c-b415ae130000 pid=5038 execve guuid=31083fac-1e00-0000-c59c-b415af130000 pid=5039 /usr/bin/dash guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=31083fac-1e00-0000-c59c-b415af130000 pid=5039 clone guuid=3b64f5ac-1e00-0000-c59c-b415b4130000 pid=5044 /usr/bin/rm guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=3b64f5ac-1e00-0000-c59c-b415b4130000 pid=5044 execve guuid=60bf39ad-1e00-0000-c59c-b415b6130000 pid=5046 /usr/bin/wget net send-data write-file guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=60bf39ad-1e00-0000-c59c-b415b6130000 pid=5046 execve guuid=ca0ad488-1f00-0000-c59c-b415fe140000 pid=5374 /usr/bin/chmod guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=ca0ad488-1f00-0000-c59c-b415fe140000 pid=5374 execve guuid=284e3189-1f00-0000-c59c-b415ff140000 pid=5375 /usr/bin/dash guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=284e3189-1f00-0000-c59c-b415ff140000 pid=5375 clone guuid=471bdf89-1f00-0000-c59c-b41501150000 pid=5377 /usr/bin/rm delete-file guuid=419dadb4-1a00-0000-c59c-b415360a0000 pid=2614->guuid=471bdf89-1f00-0000-c59c-b41501150000 pid=5377 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=0f8086f5-1a00-0000-c59c-b415490b0000 pid=2889->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=5a5c2649-1b00-0000-c59c-b415da0b0000 pid=3034->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=2bf5d63c-1d00-0000-c59c-b415800f0000 pid=3968->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=d756ad9c-1d00-0000-c59c-b41596100000 pid=4246->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=60bf39ad-1e00-0000-c59c-b415b6130000 pid=5046->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-03 14:10:08 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0bc73f1b515e2352c9c10159c8be2d7927f15291106ddb516eaaa3bf91e1b5d5

(this sample)

  
Delivery method
Distributed via web download

Comments