MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e37053c36f83c855c98cd7303315fdc2cb57e69c7c1512df43a481ee0b63708. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 3e37053c36f83c855c98cd7303315fdc2cb57e69c7c1512df43a481ee0b63708
SHA3-384 hash: 4c096a20d4e8f26bf9269fcacf022970b8ca7da8b4e09e8a5ee3708abe941467bff7c702570913f565d45be73c8063ea
SHA1 hash: fb3fd42f7f1701e02d198cd94f50c2978e06d9f1
MD5 hash: 3b68067fe3497691c871f42274adabc6
humanhash: five-snake-white-washington
File name:p
Download: download sample
File size:826 bytes
First seen:2026-06-09 15:02:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohahnk5J9F624Pj4O7:e9Qp+Mshnk5Jn624b37
TLSH T1510188CEC401DA104295E89E22D726907820C3CF26860BA87FDC443DEBA9A48B01AE89
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/jzjn/an/aelf ua-wget
http://188.132.232.81/tTxn/an/aelf ua-wget
http://188.132.232.81/AYin/an/aelf ua-wget
http://188.132.232.81/L0Sn/an/aelf ua-wget
http://188.132.232.81/vft2n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=c71dc7b1-1600-0000-5da0-c877500c0000 pid=3152 /usr/bin/sudo guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161 /tmp/sample.bin write-file guuid=c71dc7b1-1600-0000-5da0-c877500c0000 pid=3152->guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161 execve guuid=1ef4b4b4-1600-0000-5da0-c8775b0c0000 pid=3163 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=1ef4b4b4-1600-0000-5da0-c8775b0c0000 pid=3163 execve guuid=0953b6b5-1600-0000-5da0-c8775d0c0000 pid=3165 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=0953b6b5-1600-0000-5da0-c8775d0c0000 pid=3165 execve guuid=1089c9b6-1600-0000-5da0-c8775e0c0000 pid=3166 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=1089c9b6-1600-0000-5da0-c8775e0c0000 pid=3166 execve guuid=1c17c4b7-1600-0000-5da0-c8775f0c0000 pid=3167 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=1c17c4b7-1600-0000-5da0-c8775f0c0000 pid=3167 execve guuid=124f72b8-1600-0000-5da0-c877600c0000 pid=3168 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=124f72b8-1600-0000-5da0-c877600c0000 pid=3168 execve guuid=cdbb0eb9-1600-0000-5da0-c877610c0000 pid=3169 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=cdbb0eb9-1600-0000-5da0-c877610c0000 pid=3169 execve guuid=5f18acb9-1600-0000-5da0-c877620c0000 pid=3170 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5f18acb9-1600-0000-5da0-c877620c0000 pid=3170 execve guuid=8e0439bb-1600-0000-5da0-c877630c0000 pid=3171 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=8e0439bb-1600-0000-5da0-c877630c0000 pid=3171 execve guuid=7db7e5bb-1600-0000-5da0-c877640c0000 pid=3172 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=7db7e5bb-1600-0000-5da0-c877640c0000 pid=3172 execve guuid=45a98cbc-1600-0000-5da0-c877650c0000 pid=3173 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=45a98cbc-1600-0000-5da0-c877650c0000 pid=3173 execve guuid=010233bd-1600-0000-5da0-c877660c0000 pid=3174 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=010233bd-1600-0000-5da0-c877660c0000 pid=3174 execve guuid=5033cebd-1600-0000-5da0-c877670c0000 pid=3175 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5033cebd-1600-0000-5da0-c877670c0000 pid=3175 execve guuid=8b3566be-1600-0000-5da0-c877680c0000 pid=3176 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=8b3566be-1600-0000-5da0-c877680c0000 pid=3176 execve guuid=037afebe-1600-0000-5da0-c877690c0000 pid=3177 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=037afebe-1600-0000-5da0-c877690c0000 pid=3177 execve guuid=350194bf-1600-0000-5da0-c8776a0c0000 pid=3178 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=350194bf-1600-0000-5da0-c8776a0c0000 pid=3178 execve guuid=6c2f21c0-1600-0000-5da0-c8776b0c0000 pid=3179 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=6c2f21c0-1600-0000-5da0-c8776b0c0000 pid=3179 execve guuid=6ca0abc0-1600-0000-5da0-c8776c0c0000 pid=3180 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=6ca0abc0-1600-0000-5da0-c8776c0c0000 pid=3180 execve guuid=024722c1-1600-0000-5da0-c8776e0c0000 pid=3182 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=024722c1-1600-0000-5da0-c8776e0c0000 pid=3182 execve guuid=7f6ca8c1-1600-0000-5da0-c8776f0c0000 pid=3183 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=7f6ca8c1-1600-0000-5da0-c8776f0c0000 pid=3183 execve guuid=3b022dc2-1600-0000-5da0-c877700c0000 pid=3184 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=3b022dc2-1600-0000-5da0-c877700c0000 pid=3184 execve guuid=63cb9bc2-1600-0000-5da0-c877720c0000 pid=3186 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=63cb9bc2-1600-0000-5da0-c877720c0000 pid=3186 execve guuid=a73affc2-1600-0000-5da0-c877740c0000 pid=3188 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=a73affc2-1600-0000-5da0-c877740c0000 pid=3188 execve guuid=760767c3-1600-0000-5da0-c877770c0000 pid=3191 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=760767c3-1600-0000-5da0-c877770c0000 pid=3191 execve guuid=1910d5c3-1600-0000-5da0-c8777a0c0000 pid=3194 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=1910d5c3-1600-0000-5da0-c8777a0c0000 pid=3194 execve guuid=bdff3ac4-1600-0000-5da0-c8777c0c0000 pid=3196 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=bdff3ac4-1600-0000-5da0-c8777c0c0000 pid=3196 execve guuid=cb1929c5-1600-0000-5da0-c8777e0c0000 pid=3198 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=cb1929c5-1600-0000-5da0-c8777e0c0000 pid=3198 execve guuid=bd6ca5c5-1600-0000-5da0-c877800c0000 pid=3200 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=bd6ca5c5-1600-0000-5da0-c877800c0000 pid=3200 execve guuid=56cf12c6-1600-0000-5da0-c877810c0000 pid=3201 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=56cf12c6-1600-0000-5da0-c877810c0000 pid=3201 execve guuid=67368ac6-1600-0000-5da0-c877820c0000 pid=3202 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=67368ac6-1600-0000-5da0-c877820c0000 pid=3202 execve guuid=e463eec6-1600-0000-5da0-c877830c0000 pid=3203 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=e463eec6-1600-0000-5da0-c877830c0000 pid=3203 execve guuid=53e451c7-1600-0000-5da0-c877850c0000 pid=3205 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=53e451c7-1600-0000-5da0-c877850c0000 pid=3205 execve guuid=04dfa4c7-1600-0000-5da0-c877870c0000 pid=3207 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=04dfa4c7-1600-0000-5da0-c877870c0000 pid=3207 execve guuid=a7f8f4c7-1600-0000-5da0-c877890c0000 pid=3209 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=a7f8f4c7-1600-0000-5da0-c877890c0000 pid=3209 execve guuid=982263c8-1600-0000-5da0-c8778c0c0000 pid=3212 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=982263c8-1600-0000-5da0-c8778c0c0000 pid=3212 execve guuid=1325cfc8-1600-0000-5da0-c8778f0c0000 pid=3215 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=1325cfc8-1600-0000-5da0-c8778f0c0000 pid=3215 execve guuid=5c1625c9-1600-0000-5da0-c877910c0000 pid=3217 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5c1625c9-1600-0000-5da0-c877910c0000 pid=3217 execve guuid=556e82c9-1600-0000-5da0-c877930c0000 pid=3219 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=556e82c9-1600-0000-5da0-c877930c0000 pid=3219 execve guuid=3be9fac9-1600-0000-5da0-c877940c0000 pid=3220 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=3be9fac9-1600-0000-5da0-c877940c0000 pid=3220 execve guuid=490d72ca-1600-0000-5da0-c877950c0000 pid=3221 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=490d72ca-1600-0000-5da0-c877950c0000 pid=3221 execve guuid=c6b6d9ca-1600-0000-5da0-c877960c0000 pid=3222 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=c6b6d9ca-1600-0000-5da0-c877960c0000 pid=3222 execve guuid=16564acb-1600-0000-5da0-c877990c0000 pid=3225 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=16564acb-1600-0000-5da0-c877990c0000 pid=3225 execve guuid=9eb7b1cb-1600-0000-5da0-c8779c0c0000 pid=3228 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=9eb7b1cb-1600-0000-5da0-c8779c0c0000 pid=3228 execve guuid=addf17cc-1600-0000-5da0-c8779e0c0000 pid=3230 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=addf17cc-1600-0000-5da0-c8779e0c0000 pid=3230 execve guuid=3a5c76cc-1600-0000-5da0-c877a00c0000 pid=3232 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=3a5c76cc-1600-0000-5da0-c877a00c0000 pid=3232 execve guuid=860ee2cc-1600-0000-5da0-c877a10c0000 pid=3233 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=860ee2cc-1600-0000-5da0-c877a10c0000 pid=3233 execve guuid=421b42cd-1600-0000-5da0-c877a30c0000 pid=3235 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=421b42cd-1600-0000-5da0-c877a30c0000 pid=3235 execve guuid=505cc2cd-1600-0000-5da0-c877a40c0000 pid=3236 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=505cc2cd-1600-0000-5da0-c877a40c0000 pid=3236 execve guuid=15493ace-1600-0000-5da0-c877a50c0000 pid=3237 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=15493ace-1600-0000-5da0-c877a50c0000 pid=3237 execve guuid=ebcf9bce-1600-0000-5da0-c877a70c0000 pid=3239 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=ebcf9bce-1600-0000-5da0-c877a70c0000 pid=3239 execve guuid=c98ff4ce-1600-0000-5da0-c877a90c0000 pid=3241 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=c98ff4ce-1600-0000-5da0-c877a90c0000 pid=3241 execve guuid=d22a42cf-1600-0000-5da0-c877ac0c0000 pid=3244 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=d22a42cf-1600-0000-5da0-c877ac0c0000 pid=3244 execve guuid=da859acf-1600-0000-5da0-c877ae0c0000 pid=3246 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=da859acf-1600-0000-5da0-c877ae0c0000 pid=3246 execve guuid=a2b5eecf-1600-0000-5da0-c877b00c0000 pid=3248 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=a2b5eecf-1600-0000-5da0-c877b00c0000 pid=3248 execve guuid=483168d0-1600-0000-5da0-c877b30c0000 pid=3251 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=483168d0-1600-0000-5da0-c877b30c0000 pid=3251 execve guuid=e925d2d0-1600-0000-5da0-c877b60c0000 pid=3254 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=e925d2d0-1600-0000-5da0-c877b60c0000 pid=3254 execve guuid=a64a54d1-1600-0000-5da0-c877b70c0000 pid=3255 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=a64a54d1-1600-0000-5da0-c877b70c0000 pid=3255 execve guuid=aed3f5d1-1600-0000-5da0-c877b80c0000 pid=3256 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=aed3f5d1-1600-0000-5da0-c877b80c0000 pid=3256 execve guuid=3e2a9bd2-1600-0000-5da0-c877b90c0000 pid=3257 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=3e2a9bd2-1600-0000-5da0-c877b90c0000 pid=3257 execve guuid=aefa3dd3-1600-0000-5da0-c877ba0c0000 pid=3258 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=aefa3dd3-1600-0000-5da0-c877ba0c0000 pid=3258 execve guuid=de82d9d3-1600-0000-5da0-c877bb0c0000 pid=3259 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=de82d9d3-1600-0000-5da0-c877bb0c0000 pid=3259 execve guuid=eb7b68d4-1600-0000-5da0-c877bc0c0000 pid=3260 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=eb7b68d4-1600-0000-5da0-c877bc0c0000 pid=3260 execve guuid=9a94f9d4-1600-0000-5da0-c877bd0c0000 pid=3261 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=9a94f9d4-1600-0000-5da0-c877bd0c0000 pid=3261 execve guuid=d09f88d5-1600-0000-5da0-c877be0c0000 pid=3262 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=d09f88d5-1600-0000-5da0-c877be0c0000 pid=3262 execve guuid=50f80dd6-1600-0000-5da0-c877bf0c0000 pid=3263 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=50f80dd6-1600-0000-5da0-c877bf0c0000 pid=3263 execve guuid=5aaf85d6-1600-0000-5da0-c877c00c0000 pid=3264 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5aaf85d6-1600-0000-5da0-c877c00c0000 pid=3264 execve guuid=ec2a07d7-1600-0000-5da0-c877c10c0000 pid=3265 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=ec2a07d7-1600-0000-5da0-c877c10c0000 pid=3265 execve guuid=010789d7-1600-0000-5da0-c877c20c0000 pid=3266 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=010789d7-1600-0000-5da0-c877c20c0000 pid=3266 execve guuid=c7ef02d8-1600-0000-5da0-c877c30c0000 pid=3267 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=c7ef02d8-1600-0000-5da0-c877c30c0000 pid=3267 execve guuid=0eb583d8-1600-0000-5da0-c877c40c0000 pid=3268 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=0eb583d8-1600-0000-5da0-c877c40c0000 pid=3268 execve guuid=748cfcd8-1600-0000-5da0-c877c50c0000 pid=3269 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=748cfcd8-1600-0000-5da0-c877c50c0000 pid=3269 execve guuid=28d373d9-1600-0000-5da0-c877c60c0000 pid=3270 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=28d373d9-1600-0000-5da0-c877c60c0000 pid=3270 execve guuid=20b6edd9-1600-0000-5da0-c877c70c0000 pid=3271 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=20b6edd9-1600-0000-5da0-c877c70c0000 pid=3271 execve guuid=6f8325db-1600-0000-5da0-c877c80c0000 pid=3272 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=6f8325db-1600-0000-5da0-c877c80c0000 pid=3272 execve guuid=e4aa5ddc-1600-0000-5da0-c877c90c0000 pid=3273 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=e4aa5ddc-1600-0000-5da0-c877c90c0000 pid=3273 execve guuid=ab8e72dd-1600-0000-5da0-c877ca0c0000 pid=3274 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=ab8e72dd-1600-0000-5da0-c877ca0c0000 pid=3274 execve guuid=2cf365de-1600-0000-5da0-c877cb0c0000 pid=3275 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=2cf365de-1600-0000-5da0-c877cb0c0000 pid=3275 execve guuid=350750df-1600-0000-5da0-c877cc0c0000 pid=3276 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=350750df-1600-0000-5da0-c877cc0c0000 pid=3276 execve guuid=784c0ee0-1600-0000-5da0-c877cd0c0000 pid=3277 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=784c0ee0-1600-0000-5da0-c877cd0c0000 pid=3277 execve guuid=e87bbce0-1600-0000-5da0-c877ce0c0000 pid=3278 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=e87bbce0-1600-0000-5da0-c877ce0c0000 pid=3278 execve guuid=b8a254e1-1600-0000-5da0-c877cf0c0000 pid=3279 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=b8a254e1-1600-0000-5da0-c877cf0c0000 pid=3279 execve guuid=6af8dee1-1600-0000-5da0-c877d00c0000 pid=3280 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=6af8dee1-1600-0000-5da0-c877d00c0000 pid=3280 execve guuid=cb125ee2-1600-0000-5da0-c877d10c0000 pid=3281 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=cb125ee2-1600-0000-5da0-c877d10c0000 pid=3281 execve guuid=6d8ad0e2-1600-0000-5da0-c877d30c0000 pid=3283 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=6d8ad0e2-1600-0000-5da0-c877d30c0000 pid=3283 execve guuid=f7f454e3-1600-0000-5da0-c877d40c0000 pid=3284 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=f7f454e3-1600-0000-5da0-c877d40c0000 pid=3284 execve guuid=39e3cbe3-1600-0000-5da0-c877d50c0000 pid=3285 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=39e3cbe3-1600-0000-5da0-c877d50c0000 pid=3285 execve guuid=449c45e4-1600-0000-5da0-c877d70c0000 pid=3287 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=449c45e4-1600-0000-5da0-c877d70c0000 pid=3287 execve guuid=5dc0b6e4-1600-0000-5da0-c877d90c0000 pid=3289 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5dc0b6e4-1600-0000-5da0-c877d90c0000 pid=3289 execve guuid=d49e1ae5-1600-0000-5da0-c877db0c0000 pid=3291 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=d49e1ae5-1600-0000-5da0-c877db0c0000 pid=3291 execve guuid=f6508ce5-1600-0000-5da0-c877de0c0000 pid=3294 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=f6508ce5-1600-0000-5da0-c877de0c0000 pid=3294 execve guuid=49a448e6-1600-0000-5da0-c877e00c0000 pid=3296 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=49a448e6-1600-0000-5da0-c877e00c0000 pid=3296 execve guuid=510fc6e6-1600-0000-5da0-c877e10c0000 pid=3297 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=510fc6e6-1600-0000-5da0-c877e10c0000 pid=3297 execve guuid=5c7028e7-1600-0000-5da0-c877e30c0000 pid=3299 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5c7028e7-1600-0000-5da0-c877e30c0000 pid=3299 execve guuid=791391e7-1600-0000-5da0-c877e40c0000 pid=3300 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=791391e7-1600-0000-5da0-c877e40c0000 pid=3300 execve guuid=d0dffae7-1600-0000-5da0-c877e50c0000 pid=3301 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=d0dffae7-1600-0000-5da0-c877e50c0000 pid=3301 execve guuid=fb5c53e8-1600-0000-5da0-c877e70c0000 pid=3303 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=fb5c53e8-1600-0000-5da0-c877e70c0000 pid=3303 execve guuid=594face8-1600-0000-5da0-c877e90c0000 pid=3305 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=594face8-1600-0000-5da0-c877e90c0000 pid=3305 execve guuid=0d90fee8-1600-0000-5da0-c877eb0c0000 pid=3307 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=0d90fee8-1600-0000-5da0-c877eb0c0000 pid=3307 execve guuid=032554e9-1600-0000-5da0-c877ed0c0000 pid=3309 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=032554e9-1600-0000-5da0-c877ed0c0000 pid=3309 execve guuid=e836aee9-1600-0000-5da0-c877ef0c0000 pid=3311 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=e836aee9-1600-0000-5da0-c877ef0c0000 pid=3311 execve guuid=b7ca05ea-1600-0000-5da0-c877f10c0000 pid=3313 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=b7ca05ea-1600-0000-5da0-c877f10c0000 pid=3313 execve guuid=423572ea-1600-0000-5da0-c877f20c0000 pid=3314 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=423572ea-1600-0000-5da0-c877f20c0000 pid=3314 execve guuid=5ed1d6ea-1600-0000-5da0-c877f40c0000 pid=3316 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5ed1d6ea-1600-0000-5da0-c877f40c0000 pid=3316 execve guuid=9f6456eb-1600-0000-5da0-c877f50c0000 pid=3317 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=9f6456eb-1600-0000-5da0-c877f50c0000 pid=3317 execve guuid=902acfeb-1600-0000-5da0-c877f60c0000 pid=3318 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=902acfeb-1600-0000-5da0-c877f60c0000 pid=3318 execve guuid=42e43eec-1600-0000-5da0-c877f70c0000 pid=3319 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=42e43eec-1600-0000-5da0-c877f70c0000 pid=3319 execve guuid=2e98a0ec-1600-0000-5da0-c877f90c0000 pid=3321 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=2e98a0ec-1600-0000-5da0-c877f90c0000 pid=3321 execve guuid=7670fbec-1600-0000-5da0-c877fb0c0000 pid=3323 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=7670fbec-1600-0000-5da0-c877fb0c0000 pid=3323 execve guuid=bc4354ed-1600-0000-5da0-c877fd0c0000 pid=3325 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=bc4354ed-1600-0000-5da0-c877fd0c0000 pid=3325 execve guuid=8f7aafed-1600-0000-5da0-c877ff0c0000 pid=3327 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=8f7aafed-1600-0000-5da0-c877ff0c0000 pid=3327 execve guuid=74910fee-1600-0000-5da0-c877010d0000 pid=3329 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=74910fee-1600-0000-5da0-c877010d0000 pid=3329 execve guuid=bbe1aaee-1600-0000-5da0-c877030d0000 pid=3331 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=bbe1aaee-1600-0000-5da0-c877030d0000 pid=3331 execve guuid=07f275ef-1600-0000-5da0-c877040d0000 pid=3332 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=07f275ef-1600-0000-5da0-c877040d0000 pid=3332 execve guuid=aa8b7af0-1600-0000-5da0-c877050d0000 pid=3333 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=aa8b7af0-1600-0000-5da0-c877050d0000 pid=3333 execve guuid=667a89f1-1600-0000-5da0-c877060d0000 pid=3334 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=667a89f1-1600-0000-5da0-c877060d0000 pid=3334 execve guuid=eff93bf2-1600-0000-5da0-c877070d0000 pid=3335 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=eff93bf2-1600-0000-5da0-c877070d0000 pid=3335 execve guuid=3608bef2-1600-0000-5da0-c877080d0000 pid=3336 /usr/bin/ls guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=3608bef2-1600-0000-5da0-c877080d0000 pid=3336 execve guuid=b73e2cf3-1600-0000-5da0-c877090d0000 pid=3337 /usr/bin/rm guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=b73e2cf3-1600-0000-5da0-c877090d0000 pid=3337 execve guuid=c4c877f3-1600-0000-5da0-c8770a0d0000 pid=3338 /usr/bin/wget net send-data write-file guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=c4c877f3-1600-0000-5da0-c8770a0d0000 pid=3338 execve guuid=d0233252-1700-0000-5da0-c8778f0d0000 pid=3471 /usr/bin/chmod guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=d0233252-1700-0000-5da0-c8778f0d0000 pid=3471 execve guuid=53e6a552-1700-0000-5da0-c877910d0000 pid=3473 /tmp/jzj guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=53e6a552-1700-0000-5da0-c877910d0000 pid=3473 execve guuid=1807d153-1700-0000-5da0-c877950d0000 pid=3477 /usr/bin/rm guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=1807d153-1700-0000-5da0-c877950d0000 pid=3477 execve guuid=76df2354-1700-0000-5da0-c877970d0000 pid=3479 /usr/bin/wget net send-data write-file guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=76df2354-1700-0000-5da0-c877970d0000 pid=3479 execve guuid=2d0d8c5f-1700-0000-5da0-c877ac0d0000 pid=3500 /usr/bin/chmod guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=2d0d8c5f-1700-0000-5da0-c877ac0d0000 pid=3500 execve guuid=10ce0d60-1700-0000-5da0-c877ae0d0000 pid=3502 /tmp/tTx guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=10ce0d60-1700-0000-5da0-c877ae0d0000 pid=3502 execve guuid=21702c61-1700-0000-5da0-c877b20d0000 pid=3506 /usr/bin/rm guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=21702c61-1700-0000-5da0-c877b20d0000 pid=3506 execve guuid=84e68661-1700-0000-5da0-c877b40d0000 pid=3508 /usr/bin/wget net send-data write-file guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=84e68661-1700-0000-5da0-c877b40d0000 pid=3508 execve guuid=a91ffc92-1700-0000-5da0-c877140e0000 pid=3604 /usr/bin/chmod guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=a91ffc92-1700-0000-5da0-c877140e0000 pid=3604 execve guuid=e9307693-1700-0000-5da0-c877150e0000 pid=3605 /tmp/AYi guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=e9307693-1700-0000-5da0-c877150e0000 pid=3605 execve guuid=439eae94-1700-0000-5da0-c877170e0000 pid=3607 /usr/bin/rm guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=439eae94-1700-0000-5da0-c877170e0000 pid=3607 execve guuid=fe171295-1700-0000-5da0-c877180e0000 pid=3608 /usr/bin/wget net send-data write-file guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=fe171295-1700-0000-5da0-c877180e0000 pid=3608 execve guuid=0f4770a0-1700-0000-5da0-c877270e0000 pid=3623 /usr/bin/chmod guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=0f4770a0-1700-0000-5da0-c877270e0000 pid=3623 execve guuid=7271e6a0-1700-0000-5da0-c877280e0000 pid=3624 /tmp/L0S guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=7271e6a0-1700-0000-5da0-c877280e0000 pid=3624 execve guuid=fd5f16a2-1700-0000-5da0-c8772c0e0000 pid=3628 /usr/bin/rm guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=fd5f16a2-1700-0000-5da0-c8772c0e0000 pid=3628 execve guuid=5346b1a2-1700-0000-5da0-c8772e0e0000 pid=3630 /usr/bin/wget net send-data write-file guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=5346b1a2-1700-0000-5da0-c8772e0e0000 pid=3630 execve guuid=dd1ef926-1800-0000-5da0-c877200f0000 pid=3872 /usr/bin/chmod guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=dd1ef926-1800-0000-5da0-c877200f0000 pid=3872 execve guuid=c8cb7327-1800-0000-5da0-c877220f0000 pid=3874 /tmp/vft2 guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=c8cb7327-1800-0000-5da0-c877220f0000 pid=3874 execve guuid=fc33e328-1800-0000-5da0-c877260f0000 pid=3878 /usr/bin/rm delete-file guuid=d5e77fb4-1600-0000-5da0-c877590c0000 pid=3161->guuid=fc33e328-1800-0000-5da0-c877260f0000 pid=3878 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=c4c877f3-1600-0000-5da0-c8770a0d0000 pid=3338->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=76df2354-1700-0000-5da0-c877970d0000 pid=3479->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=84e68661-1700-0000-5da0-c877b40d0000 pid=3508->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=fe171295-1700-0000-5da0-c877180e0000 pid=3608->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=5346b1a2-1700-0000-5da0-c8772e0e0000 pid=3630->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-09 15:03:42 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3e37053c36f83c855c98cd7303315fdc2cb57e69c7c1512df43a481ee0b63708

(this sample)

  
Delivery method
Distributed via web download

Comments