MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35e66da427a1ad60fd9de1d0efc5ae98275cea581d21e2aebca59491b936caec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 35e66da427a1ad60fd9de1d0efc5ae98275cea581d21e2aebca59491b936caec
SHA3-384 hash: 54755efe57a8bf627a8b8e9d7ce28bb8ec0eae14038a2be3600fc20986fc1f600affdf53c178259a6201b58d0fe29877
SHA1 hash: 13e0e3aabbbfa542c75a0a468474a7585b850207
MD5 hash: fdd1d37f1b6cc05cf665577aa6df3f46
humanhash: fruit-fourteen-river-quebec
File name:p
Download: download sample
File size:839 bytes
First seen:2026-06-21 08:49:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaFvftirT/epviIvz0O7:e9Qp+MsFvfITIBYO7
TLSH T19D0148D686417D105059DA9972979290B812D3CE094F0FB87FDC5E3DFB88D14B066E94
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/4eyn/an/an/a
http://129.121.114.124/F6nn/an/an/a
http://129.121.114.124/V6DLn/an/an/a
http://129.121.114.124/VuGUn/an/an/a
http://129.121.114.124/LdFqn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=881e1659-1900-0000-ff65-3c65410f0000 pid=3905 /usr/bin/sudo guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910 /tmp/sample.bin write-file guuid=881e1659-1900-0000-ff65-3c65410f0000 pid=3905->guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910 execve guuid=942b5b5b-1900-0000-ff65-3c65480f0000 pid=3912 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=942b5b5b-1900-0000-ff65-3c65480f0000 pid=3912 execve guuid=f45e375c-1900-0000-ff65-3c654c0f0000 pid=3916 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f45e375c-1900-0000-ff65-3c654c0f0000 pid=3916 execve guuid=5ad1965c-1900-0000-ff65-3c654e0f0000 pid=3918 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=5ad1965c-1900-0000-ff65-3c654e0f0000 pid=3918 execve guuid=2c11ef5c-1900-0000-ff65-3c65510f0000 pid=3921 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2c11ef5c-1900-0000-ff65-3c65510f0000 pid=3921 execve guuid=b2c4485d-1900-0000-ff65-3c65530f0000 pid=3923 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=b2c4485d-1900-0000-ff65-3c65530f0000 pid=3923 execve guuid=2bb0a55d-1900-0000-ff65-3c65550f0000 pid=3925 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2bb0a55d-1900-0000-ff65-3c65550f0000 pid=3925 execve guuid=96cc045e-1900-0000-ff65-3c65580f0000 pid=3928 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=96cc045e-1900-0000-ff65-3c65580f0000 pid=3928 execve guuid=28c05e5e-1900-0000-ff65-3c655a0f0000 pid=3930 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=28c05e5e-1900-0000-ff65-3c655a0f0000 pid=3930 execve guuid=b50fb75e-1900-0000-ff65-3c655e0f0000 pid=3934 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=b50fb75e-1900-0000-ff65-3c655e0f0000 pid=3934 execve guuid=35a91e5f-1900-0000-ff65-3c65600f0000 pid=3936 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=35a91e5f-1900-0000-ff65-3c65600f0000 pid=3936 execve guuid=0c86825f-1900-0000-ff65-3c65630f0000 pid=3939 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0c86825f-1900-0000-ff65-3c65630f0000 pid=3939 execve guuid=99f9f25f-1900-0000-ff65-3c65660f0000 pid=3942 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=99f9f25f-1900-0000-ff65-3c65660f0000 pid=3942 execve guuid=1e344f60-1900-0000-ff65-3c656a0f0000 pid=3946 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=1e344f60-1900-0000-ff65-3c656a0f0000 pid=3946 execve guuid=bda8d260-1900-0000-ff65-3c656b0f0000 pid=3947 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bda8d260-1900-0000-ff65-3c656b0f0000 pid=3947 execve guuid=2bee4961-1900-0000-ff65-3c656f0f0000 pid=3951 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2bee4961-1900-0000-ff65-3c656f0f0000 pid=3951 execve guuid=2363b461-1900-0000-ff65-3c65710f0000 pid=3953 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2363b461-1900-0000-ff65-3c65710f0000 pid=3953 execve guuid=baff1862-1900-0000-ff65-3c65740f0000 pid=3956 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=baff1862-1900-0000-ff65-3c65740f0000 pid=3956 execve guuid=fce77662-1900-0000-ff65-3c65760f0000 pid=3958 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=fce77662-1900-0000-ff65-3c65760f0000 pid=3958 execve guuid=5be3d762-1900-0000-ff65-3c65780f0000 pid=3960 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=5be3d762-1900-0000-ff65-3c65780f0000 pid=3960 execve guuid=b5253b63-1900-0000-ff65-3c657b0f0000 pid=3963 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=b5253b63-1900-0000-ff65-3c657b0f0000 pid=3963 execve guuid=ce9b9b63-1900-0000-ff65-3c657d0f0000 pid=3965 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=ce9b9b63-1900-0000-ff65-3c657d0f0000 pid=3965 execve guuid=57dc0664-1900-0000-ff65-3c65810f0000 pid=3969 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=57dc0664-1900-0000-ff65-3c65810f0000 pid=3969 execve guuid=7be26464-1900-0000-ff65-3c65850f0000 pid=3973 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=7be26464-1900-0000-ff65-3c65850f0000 pid=3973 execve guuid=9bdabb64-1900-0000-ff65-3c65870f0000 pid=3975 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=9bdabb64-1900-0000-ff65-3c65870f0000 pid=3975 execve guuid=936e1765-1900-0000-ff65-3c65890f0000 pid=3977 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=936e1765-1900-0000-ff65-3c65890f0000 pid=3977 execve guuid=e23d7365-1900-0000-ff65-3c658b0f0000 pid=3979 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=e23d7365-1900-0000-ff65-3c658b0f0000 pid=3979 execve guuid=e9a4d065-1900-0000-ff65-3c658e0f0000 pid=3982 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=e9a4d065-1900-0000-ff65-3c658e0f0000 pid=3982 execve guuid=da782e66-1900-0000-ff65-3c65900f0000 pid=3984 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=da782e66-1900-0000-ff65-3c65900f0000 pid=3984 execve guuid=f7f78766-1900-0000-ff65-3c65920f0000 pid=3986 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f7f78766-1900-0000-ff65-3c65920f0000 pid=3986 execve guuid=c1dde366-1900-0000-ff65-3c65940f0000 pid=3988 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=c1dde366-1900-0000-ff65-3c65940f0000 pid=3988 execve guuid=17fd3f67-1900-0000-ff65-3c65980f0000 pid=3992 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=17fd3f67-1900-0000-ff65-3c65980f0000 pid=3992 execve guuid=4088b067-1900-0000-ff65-3c659c0f0000 pid=3996 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=4088b067-1900-0000-ff65-3c659c0f0000 pid=3996 execve guuid=bf402268-1900-0000-ff65-3c659e0f0000 pid=3998 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bf402268-1900-0000-ff65-3c659e0f0000 pid=3998 execve guuid=d17c8168-1900-0000-ff65-3c65a00f0000 pid=4000 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=d17c8168-1900-0000-ff65-3c65a00f0000 pid=4000 execve guuid=6404e768-1900-0000-ff65-3c65a40f0000 pid=4004 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=6404e768-1900-0000-ff65-3c65a40f0000 pid=4004 execve guuid=40494769-1900-0000-ff65-3c65a80f0000 pid=4008 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=40494769-1900-0000-ff65-3c65a80f0000 pid=4008 execve guuid=bfd3a569-1900-0000-ff65-3c65aa0f0000 pid=4010 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bfd3a569-1900-0000-ff65-3c65aa0f0000 pid=4010 execve guuid=6029046a-1900-0000-ff65-3c65ad0f0000 pid=4013 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=6029046a-1900-0000-ff65-3c65ad0f0000 pid=4013 execve guuid=4eab5b6a-1900-0000-ff65-3c65af0f0000 pid=4015 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=4eab5b6a-1900-0000-ff65-3c65af0f0000 pid=4015 execve guuid=f30cb26a-1900-0000-ff65-3c65b10f0000 pid=4017 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f30cb26a-1900-0000-ff65-3c65b10f0000 pid=4017 execve guuid=9425096b-1900-0000-ff65-3c65b40f0000 pid=4020 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=9425096b-1900-0000-ff65-3c65b40f0000 pid=4020 execve guuid=f6f1766b-1900-0000-ff65-3c65b60f0000 pid=4022 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f6f1766b-1900-0000-ff65-3c65b60f0000 pid=4022 execve guuid=0aabdd6b-1900-0000-ff65-3c65b80f0000 pid=4024 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0aabdd6b-1900-0000-ff65-3c65b80f0000 pid=4024 execve guuid=1da5406c-1900-0000-ff65-3c65bc0f0000 pid=4028 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=1da5406c-1900-0000-ff65-3c65bc0f0000 pid=4028 execve guuid=0e26ac6c-1900-0000-ff65-3c65bd0f0000 pid=4029 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0e26ac6c-1900-0000-ff65-3c65bd0f0000 pid=4029 execve guuid=bc0a0e6d-1900-0000-ff65-3c65c00f0000 pid=4032 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bc0a0e6d-1900-0000-ff65-3c65c00f0000 pid=4032 execve guuid=0648c26d-1900-0000-ff65-3c65c50f0000 pid=4037 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0648c26d-1900-0000-ff65-3c65c50f0000 pid=4037 execve guuid=dede246e-1900-0000-ff65-3c65c90f0000 pid=4041 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=dede246e-1900-0000-ff65-3c65c90f0000 pid=4041 execve guuid=d1127c6e-1900-0000-ff65-3c65cb0f0000 pid=4043 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=d1127c6e-1900-0000-ff65-3c65cb0f0000 pid=4043 execve guuid=1512d56e-1900-0000-ff65-3c65ce0f0000 pid=4046 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=1512d56e-1900-0000-ff65-3c65ce0f0000 pid=4046 execve guuid=9b882d6f-1900-0000-ff65-3c65d10f0000 pid=4049 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=9b882d6f-1900-0000-ff65-3c65d10f0000 pid=4049 execve guuid=0df08a6f-1900-0000-ff65-3c65d30f0000 pid=4051 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0df08a6f-1900-0000-ff65-3c65d30f0000 pid=4051 execve guuid=f4fde36f-1900-0000-ff65-3c65d60f0000 pid=4054 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f4fde36f-1900-0000-ff65-3c65d60f0000 pid=4054 execve guuid=97e53170-1900-0000-ff65-3c65d80f0000 pid=4056 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=97e53170-1900-0000-ff65-3c65d80f0000 pid=4056 execve guuid=26569270-1900-0000-ff65-3c65da0f0000 pid=4058 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=26569270-1900-0000-ff65-3c65da0f0000 pid=4058 execve guuid=826bf770-1900-0000-ff65-3c65dc0f0000 pid=4060 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=826bf770-1900-0000-ff65-3c65dc0f0000 pid=4060 execve guuid=a9137971-1900-0000-ff65-3c65dd0f0000 pid=4061 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=a9137971-1900-0000-ff65-3c65dd0f0000 pid=4061 execve guuid=bf85df71-1900-0000-ff65-3c65e10f0000 pid=4065 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bf85df71-1900-0000-ff65-3c65e10f0000 pid=4065 execve guuid=64bc4e72-1900-0000-ff65-3c65e20f0000 pid=4066 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=64bc4e72-1900-0000-ff65-3c65e20f0000 pid=4066 execve guuid=1a7ba272-1900-0000-ff65-3c65e60f0000 pid=4070 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=1a7ba272-1900-0000-ff65-3c65e60f0000 pid=4070 execve guuid=85221673-1900-0000-ff65-3c65e70f0000 pid=4071 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=85221673-1900-0000-ff65-3c65e70f0000 pid=4071 execve guuid=d9616773-1900-0000-ff65-3c65e90f0000 pid=4073 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=d9616773-1900-0000-ff65-3c65e90f0000 pid=4073 execve guuid=772dcb73-1900-0000-ff65-3c65ec0f0000 pid=4076 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=772dcb73-1900-0000-ff65-3c65ec0f0000 pid=4076 execve guuid=17dc2c74-1900-0000-ff65-3c65ee0f0000 pid=4078 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=17dc2c74-1900-0000-ff65-3c65ee0f0000 pid=4078 execve guuid=2ebd9574-1900-0000-ff65-3c65f10f0000 pid=4081 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2ebd9574-1900-0000-ff65-3c65f10f0000 pid=4081 execve guuid=28e2fa74-1900-0000-ff65-3c65f40f0000 pid=4084 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=28e2fa74-1900-0000-ff65-3c65f40f0000 pid=4084 execve guuid=9e6d5975-1900-0000-ff65-3c65f50f0000 pid=4085 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=9e6d5975-1900-0000-ff65-3c65f50f0000 pid=4085 execve guuid=3b5cc375-1900-0000-ff65-3c65f90f0000 pid=4089 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=3b5cc375-1900-0000-ff65-3c65f90f0000 pid=4089 execve guuid=5e912876-1900-0000-ff65-3c65fd0f0000 pid=4093 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=5e912876-1900-0000-ff65-3c65fd0f0000 pid=4093 execve guuid=db858b76-1900-0000-ff65-3c65ff0f0000 pid=4095 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=db858b76-1900-0000-ff65-3c65ff0f0000 pid=4095 execve guuid=cc24ed76-1900-0000-ff65-3c6502100000 pid=4098 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=cc24ed76-1900-0000-ff65-3c6502100000 pid=4098 execve guuid=2f834977-1900-0000-ff65-3c6504100000 pid=4100 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2f834977-1900-0000-ff65-3c6504100000 pid=4100 execve guuid=b758a377-1900-0000-ff65-3c6506100000 pid=4102 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=b758a377-1900-0000-ff65-3c6506100000 pid=4102 execve guuid=f97efe77-1900-0000-ff65-3c6509100000 pid=4105 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f97efe77-1900-0000-ff65-3c6509100000 pid=4105 execve guuid=bb245e78-1900-0000-ff65-3c650b100000 pid=4107 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bb245e78-1900-0000-ff65-3c650b100000 pid=4107 execve guuid=0889ba78-1900-0000-ff65-3c650f100000 pid=4111 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0889ba78-1900-0000-ff65-3c650f100000 pid=4111 execve guuid=c48c2879-1900-0000-ff65-3c6510100000 pid=4112 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=c48c2879-1900-0000-ff65-3c6510100000 pid=4112 execve guuid=91849879-1900-0000-ff65-3c6514100000 pid=4116 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=91849879-1900-0000-ff65-3c6514100000 pid=4116 execve guuid=87410c7a-1900-0000-ff65-3c6515100000 pid=4117 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=87410c7a-1900-0000-ff65-3c6515100000 pid=4117 execve guuid=bad3727a-1900-0000-ff65-3c6516100000 pid=4118 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bad3727a-1900-0000-ff65-3c6516100000 pid=4118 execve guuid=841bd37a-1900-0000-ff65-3c6518100000 pid=4120 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=841bd37a-1900-0000-ff65-3c6518100000 pid=4120 execve guuid=172c377b-1900-0000-ff65-3c651a100000 pid=4122 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=172c377b-1900-0000-ff65-3c651a100000 pid=4122 execve guuid=52bc9a7b-1900-0000-ff65-3c651d100000 pid=4125 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=52bc9a7b-1900-0000-ff65-3c651d100000 pid=4125 execve guuid=4198037c-1900-0000-ff65-3c651f100000 pid=4127 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=4198037c-1900-0000-ff65-3c651f100000 pid=4127 execve guuid=0972667c-1900-0000-ff65-3c6521100000 pid=4129 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0972667c-1900-0000-ff65-3c6521100000 pid=4129 execve guuid=c382c37c-1900-0000-ff65-3c6524100000 pid=4132 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=c382c37c-1900-0000-ff65-3c6524100000 pid=4132 execve guuid=de89267d-1900-0000-ff65-3c6525100000 pid=4133 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=de89267d-1900-0000-ff65-3c6525100000 pid=4133 execve guuid=629da87d-1900-0000-ff65-3c6526100000 pid=4134 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=629da87d-1900-0000-ff65-3c6526100000 pid=4134 execve guuid=050e0e7e-1900-0000-ff65-3c652a100000 pid=4138 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=050e0e7e-1900-0000-ff65-3c652a100000 pid=4138 execve guuid=058c6a7e-1900-0000-ff65-3c652e100000 pid=4142 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=058c6a7e-1900-0000-ff65-3c652e100000 pid=4142 execve guuid=037dca7e-1900-0000-ff65-3c6530100000 pid=4144 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=037dca7e-1900-0000-ff65-3c6530100000 pid=4144 execve guuid=28e2367f-1900-0000-ff65-3c6532100000 pid=4146 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=28e2367f-1900-0000-ff65-3c6532100000 pid=4146 execve guuid=25279d7f-1900-0000-ff65-3c6536100000 pid=4150 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=25279d7f-1900-0000-ff65-3c6536100000 pid=4150 execve guuid=35210580-1900-0000-ff65-3c653a100000 pid=4154 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=35210580-1900-0000-ff65-3c653a100000 pid=4154 execve guuid=c4cc7480-1900-0000-ff65-3c653d100000 pid=4157 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=c4cc7480-1900-0000-ff65-3c653d100000 pid=4157 execve guuid=75d3df80-1900-0000-ff65-3c6541100000 pid=4161 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=75d3df80-1900-0000-ff65-3c6541100000 pid=4161 execve guuid=ba705181-1900-0000-ff65-3c6545100000 pid=4165 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=ba705181-1900-0000-ff65-3c6545100000 pid=4165 execve guuid=d5afc081-1900-0000-ff65-3c6548100000 pid=4168 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=d5afc081-1900-0000-ff65-3c6548100000 pid=4168 execve guuid=93722882-1900-0000-ff65-3c654c100000 pid=4172 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=93722882-1900-0000-ff65-3c654c100000 pid=4172 execve guuid=9c319582-1900-0000-ff65-3c6550100000 pid=4176 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=9c319582-1900-0000-ff65-3c6550100000 pid=4176 execve guuid=bff60283-1900-0000-ff65-3c6552100000 pid=4178 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bff60283-1900-0000-ff65-3c6552100000 pid=4178 execve guuid=386e5f83-1900-0000-ff65-3c6555100000 pid=4181 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=386e5f83-1900-0000-ff65-3c6555100000 pid=4181 execve guuid=7cd1cf83-1900-0000-ff65-3c6557100000 pid=4183 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=7cd1cf83-1900-0000-ff65-3c6557100000 pid=4183 execve guuid=cf623984-1900-0000-ff65-3c655a100000 pid=4186 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=cf623984-1900-0000-ff65-3c655a100000 pid=4186 execve guuid=cea4b184-1900-0000-ff65-3c655c100000 pid=4188 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=cea4b184-1900-0000-ff65-3c655c100000 pid=4188 execve guuid=b2451c85-1900-0000-ff65-3c6560100000 pid=4192 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=b2451c85-1900-0000-ff65-3c6560100000 pid=4192 execve guuid=64559b85-1900-0000-ff65-3c6563100000 pid=4195 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=64559b85-1900-0000-ff65-3c6563100000 pid=4195 execve guuid=02790b86-1900-0000-ff65-3c6566100000 pid=4198 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=02790b86-1900-0000-ff65-3c6566100000 pid=4198 execve guuid=698a6f86-1900-0000-ff65-3c6568100000 pid=4200 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=698a6f86-1900-0000-ff65-3c6568100000 pid=4200 execve guuid=df33cd86-1900-0000-ff65-3c656b100000 pid=4203 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=df33cd86-1900-0000-ff65-3c656b100000 pid=4203 execve guuid=cd594287-1900-0000-ff65-3c656d100000 pid=4205 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=cd594287-1900-0000-ff65-3c656d100000 pid=4205 execve guuid=a9e1aa87-1900-0000-ff65-3c656f100000 pid=4207 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=a9e1aa87-1900-0000-ff65-3c656f100000 pid=4207 execve guuid=0cf91e88-1900-0000-ff65-3c6570100000 pid=4208 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0cf91e88-1900-0000-ff65-3c6570100000 pid=4208 execve guuid=71c2bc88-1900-0000-ff65-3c6571100000 pid=4209 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=71c2bc88-1900-0000-ff65-3c6571100000 pid=4209 execve guuid=bb9a6189-1900-0000-ff65-3c6572100000 pid=4210 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=bb9a6189-1900-0000-ff65-3c6572100000 pid=4210 execve guuid=3f6be389-1900-0000-ff65-3c6576100000 pid=4214 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=3f6be389-1900-0000-ff65-3c6576100000 pid=4214 execve guuid=337e6b8a-1900-0000-ff65-3c6577100000 pid=4215 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=337e6b8a-1900-0000-ff65-3c6577100000 pid=4215 execve guuid=a39c3f8b-1900-0000-ff65-3c657b100000 pid=4219 /usr/bin/ls guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=a39c3f8b-1900-0000-ff65-3c657b100000 pid=4219 execve guuid=7052a38b-1900-0000-ff65-3c657f100000 pid=4223 /usr/bin/rm guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=7052a38b-1900-0000-ff65-3c657f100000 pid=4223 execve guuid=2454df8b-1900-0000-ff65-3c6580100000 pid=4224 /usr/bin/wget net send-data write-file guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2454df8b-1900-0000-ff65-3c6580100000 pid=4224 execve guuid=20c8f89a-1900-0000-ff65-3c65c7100000 pid=4295 /usr/bin/chmod guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=20c8f89a-1900-0000-ff65-3c65c7100000 pid=4295 execve guuid=0b2c379b-1900-0000-ff65-3c65ca100000 pid=4298 /tmp/4ey guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=0b2c379b-1900-0000-ff65-3c65ca100000 pid=4298 execve guuid=7a0c209c-1900-0000-ff65-3c65d1100000 pid=4305 /usr/bin/rm guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=7a0c209c-1900-0000-ff65-3c65d1100000 pid=4305 execve guuid=e4246b9c-1900-0000-ff65-3c65d5100000 pid=4309 /usr/bin/wget net send-data write-file guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=e4246b9c-1900-0000-ff65-3c65d5100000 pid=4309 execve guuid=28ad41aa-1900-0000-ff65-3c650a110000 pid=4362 /usr/bin/chmod guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=28ad41aa-1900-0000-ff65-3c650a110000 pid=4362 execve guuid=81718faa-1900-0000-ff65-3c650c110000 pid=4364 /tmp/F6n guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=81718faa-1900-0000-ff65-3c650c110000 pid=4364 execve guuid=61bef0ab-1900-0000-ff65-3c650f110000 pid=4367 /usr/bin/rm guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=61bef0ab-1900-0000-ff65-3c650f110000 pid=4367 execve guuid=50eb58ac-1900-0000-ff65-3c6510110000 pid=4368 /usr/bin/wget net send-data write-file guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=50eb58ac-1900-0000-ff65-3c6510110000 pid=4368 execve guuid=708afeba-1900-0000-ff65-3c6536110000 pid=4406 /usr/bin/chmod guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=708afeba-1900-0000-ff65-3c6536110000 pid=4406 execve guuid=f59b8dbb-1900-0000-ff65-3c6538110000 pid=4408 /tmp/V6DL guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=f59b8dbb-1900-0000-ff65-3c6538110000 pid=4408 execve guuid=445ccfbc-1900-0000-ff65-3c653d110000 pid=4413 /usr/bin/rm guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=445ccfbc-1900-0000-ff65-3c653d110000 pid=4413 execve guuid=abdb11bd-1900-0000-ff65-3c653f110000 pid=4415 /usr/bin/wget net send-data write-file guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=abdb11bd-1900-0000-ff65-3c653f110000 pid=4415 execve guuid=2e6818ca-1900-0000-ff65-3c6560110000 pid=4448 /usr/bin/chmod guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=2e6818ca-1900-0000-ff65-3c6560110000 pid=4448 execve guuid=11bf92ca-1900-0000-ff65-3c6562110000 pid=4450 /tmp/VuGU guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=11bf92ca-1900-0000-ff65-3c6562110000 pid=4450 execve guuid=8cd3ebcb-1900-0000-ff65-3c6567110000 pid=4455 /usr/bin/rm guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=8cd3ebcb-1900-0000-ff65-3c6567110000 pid=4455 execve guuid=3462cacc-1900-0000-ff65-3c656a110000 pid=4458 /usr/bin/wget net send-data write-file guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=3462cacc-1900-0000-ff65-3c656a110000 pid=4458 execve guuid=222c8dda-1900-0000-ff65-3c6591110000 pid=4497 /usr/bin/chmod guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=222c8dda-1900-0000-ff65-3c6591110000 pid=4497 execve guuid=ffe2feda-1900-0000-ff65-3c6593110000 pid=4499 /tmp/LdFq guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=ffe2feda-1900-0000-ff65-3c6593110000 pid=4499 execve guuid=9ff339dd-1900-0000-ff65-3c659a110000 pid=4506 /usr/bin/rm delete-file guuid=7d76235b-1900-0000-ff65-3c65460f0000 pid=3910->guuid=9ff339dd-1900-0000-ff65-3c659a110000 pid=4506 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=2454df8b-1900-0000-ff65-3c6580100000 pid=4224->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=e4246b9c-1900-0000-ff65-3c65d5100000 pid=4309->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=50eb58ac-1900-0000-ff65-3c6510110000 pid=4368->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=abdb11bd-1900-0000-ff65-3c653f110000 pid=4415->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=3462cacc-1900-0000-ff65-3c656a110000 pid=4458->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 35e66da427a1ad60fd9de1d0efc5ae98275cea581d21e2aebca59491b936caec

(this sample)

  
Delivery method
Distributed via web download

Comments