MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 505341cbb6e1bd79ea2a4816d42441bec8d7d0ab131d37232ea555cb80abeca9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 505341cbb6e1bd79ea2a4816d42441bec8d7d0ab131d37232ea555cb80abeca9
SHA3-384 hash: 283a272714c9e71e57bcb82265c90d83c24249706a7b1044c9ad1e052a31bb7344a3bad996f7761b6bc648f4d558349b
SHA1 hash: f5e1f9c0d03e26bec67dec8d73115871a111af73
MD5 hash: 1df0827f454572fb972357da2a302027
humanhash: bravo-monkey-low-lithium
File name:p
Download: download sample
File size:830 bytes
First seen:2026-06-09 20:44:37 UTC
Last seen:2026-06-10 12:24:54 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkajIZbp7esGIuABalOsv3I2QYEFkIsusH1Z:kXCKysE2hi0ziQvZohajxLddxE+PDl7
TLSH T18001ABCEC0129B6041C6E89E23D76180BC20C3CB56454FF87E9C803DDBBC6887069F99
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/j3Kn/an/aelf ua-wget
http://188.132.232.81/veMyn/an/aelf ua-wget
http://188.132.232.81/GMln/an/aelf ua-wget
http://188.132.232.81/Mod1n/an/aelf ua-wget
http://188.132.232.81/GgXn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=33ad2884-1900-0000-6463-4185820b0000 pid=2946 /usr/bin/sudo guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951 /tmp/sample.bin write-file guuid=33ad2884-1900-0000-6463-4185820b0000 pid=2946->guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951 execve guuid=2a658486-1900-0000-6463-41858a0b0000 pid=2954 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=2a658486-1900-0000-6463-41858a0b0000 pid=2954 execve guuid=7f3a4987-1900-0000-6463-41858d0b0000 pid=2957 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=7f3a4987-1900-0000-6463-41858d0b0000 pid=2957 execve guuid=5106b187-1900-0000-6463-41858f0b0000 pid=2959 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=5106b187-1900-0000-6463-41858f0b0000 pid=2959 execve guuid=f4521b88-1900-0000-6463-4185910b0000 pid=2961 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f4521b88-1900-0000-6463-4185910b0000 pid=2961 execve guuid=96c29888-1900-0000-6463-4185920b0000 pid=2962 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=96c29888-1900-0000-6463-4185920b0000 pid=2962 execve guuid=300e0b89-1900-0000-6463-4185940b0000 pid=2964 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=300e0b89-1900-0000-6463-4185940b0000 pid=2964 execve guuid=5cac6c89-1900-0000-6463-4185960b0000 pid=2966 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=5cac6c89-1900-0000-6463-4185960b0000 pid=2966 execve guuid=f4fac489-1900-0000-6463-4185980b0000 pid=2968 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f4fac489-1900-0000-6463-4185980b0000 pid=2968 execve guuid=19231e8a-1900-0000-6463-41859b0b0000 pid=2971 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=19231e8a-1900-0000-6463-41859b0b0000 pid=2971 execve guuid=d3387f8a-1900-0000-6463-41859d0b0000 pid=2973 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=d3387f8a-1900-0000-6463-41859d0b0000 pid=2973 execve guuid=3db1e88a-1900-0000-6463-41859f0b0000 pid=2975 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=3db1e88a-1900-0000-6463-41859f0b0000 pid=2975 execve guuid=92f8748b-1900-0000-6463-4185a10b0000 pid=2977 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=92f8748b-1900-0000-6463-4185a10b0000 pid=2977 execve guuid=b921448c-1900-0000-6463-4185a30b0000 pid=2979 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=b921448c-1900-0000-6463-4185a30b0000 pid=2979 execve guuid=2031ba8c-1900-0000-6463-4185a40b0000 pid=2980 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=2031ba8c-1900-0000-6463-4185a40b0000 pid=2980 execve guuid=bcad278d-1900-0000-6463-4185a60b0000 pid=2982 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=bcad278d-1900-0000-6463-4185a60b0000 pid=2982 execve guuid=141d908d-1900-0000-6463-4185a80b0000 pid=2984 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=141d908d-1900-0000-6463-4185a80b0000 pid=2984 execve guuid=a0bdf38d-1900-0000-6463-4185ab0b0000 pid=2987 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a0bdf38d-1900-0000-6463-4185ab0b0000 pid=2987 execve guuid=ec305b8e-1900-0000-6463-4185ad0b0000 pid=2989 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=ec305b8e-1900-0000-6463-4185ad0b0000 pid=2989 execve guuid=60f9c08e-1900-0000-6463-4185b00b0000 pid=2992 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=60f9c08e-1900-0000-6463-4185b00b0000 pid=2992 execve guuid=0993208f-1900-0000-6463-4185b20b0000 pid=2994 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=0993208f-1900-0000-6463-4185b20b0000 pid=2994 execve guuid=9a05828f-1900-0000-6463-4185b50b0000 pid=2997 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=9a05828f-1900-0000-6463-4185b50b0000 pid=2997 execve guuid=b6badf8f-1900-0000-6463-4185b70b0000 pid=2999 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=b6badf8f-1900-0000-6463-4185b70b0000 pid=2999 execve guuid=d6be8c90-1900-0000-6463-4185b90b0000 pid=3001 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=d6be8c90-1900-0000-6463-4185b90b0000 pid=3001 execve guuid=6a18e990-1900-0000-6463-4185bb0b0000 pid=3003 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6a18e990-1900-0000-6463-4185bb0b0000 pid=3003 execve guuid=6e774591-1900-0000-6463-4185bd0b0000 pid=3005 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6e774591-1900-0000-6463-4185bd0b0000 pid=3005 execve guuid=cd97a491-1900-0000-6463-4185bf0b0000 pid=3007 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=cd97a491-1900-0000-6463-4185bf0b0000 pid=3007 execve guuid=86e8fe91-1900-0000-6463-4185c10b0000 pid=3009 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=86e8fe91-1900-0000-6463-4185c10b0000 pid=3009 execve guuid=f32c5d92-1900-0000-6463-4185c30b0000 pid=3011 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f32c5d92-1900-0000-6463-4185c30b0000 pid=3011 execve guuid=2784b992-1900-0000-6463-4185c50b0000 pid=3013 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=2784b992-1900-0000-6463-4185c50b0000 pid=3013 execve guuid=492e2893-1900-0000-6463-4185c60b0000 pid=3014 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=492e2893-1900-0000-6463-4185c60b0000 pid=3014 execve guuid=a4839193-1900-0000-6463-4185c80b0000 pid=3016 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a4839193-1900-0000-6463-4185c80b0000 pid=3016 execve guuid=c6b10e94-1900-0000-6463-4185c90b0000 pid=3017 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=c6b10e94-1900-0000-6463-4185c90b0000 pid=3017 execve guuid=30e27f94-1900-0000-6463-4185ca0b0000 pid=3018 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=30e27f94-1900-0000-6463-4185ca0b0000 pid=3018 execve guuid=c19be994-1900-0000-6463-4185cb0b0000 pid=3019 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=c19be994-1900-0000-6463-4185cb0b0000 pid=3019 execve guuid=69674695-1900-0000-6463-4185ce0b0000 pid=3022 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=69674695-1900-0000-6463-4185ce0b0000 pid=3022 execve guuid=edda2e96-1900-0000-6463-4185d10b0000 pid=3025 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=edda2e96-1900-0000-6463-4185d10b0000 pid=3025 execve guuid=db47ea96-1900-0000-6463-4185d50b0000 pid=3029 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=db47ea96-1900-0000-6463-4185d50b0000 pid=3029 execve guuid=dd01a197-1900-0000-6463-4185d80b0000 pid=3032 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=dd01a197-1900-0000-6463-4185d80b0000 pid=3032 execve guuid=0c7a6498-1900-0000-6463-4185da0b0000 pid=3034 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=0c7a6498-1900-0000-6463-4185da0b0000 pid=3034 execve guuid=4f0ad098-1900-0000-6463-4185dc0b0000 pid=3036 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=4f0ad098-1900-0000-6463-4185dc0b0000 pid=3036 execve guuid=5a984f99-1900-0000-6463-4185dd0b0000 pid=3037 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=5a984f99-1900-0000-6463-4185dd0b0000 pid=3037 execve guuid=f96cc799-1900-0000-6463-4185df0b0000 pid=3039 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f96cc799-1900-0000-6463-4185df0b0000 pid=3039 execve guuid=5f09269a-1900-0000-6463-4185e10b0000 pid=3041 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=5f09269a-1900-0000-6463-4185e10b0000 pid=3041 execve guuid=3091809a-1900-0000-6463-4185e30b0000 pid=3043 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=3091809a-1900-0000-6463-4185e30b0000 pid=3043 execve guuid=4487d59a-1900-0000-6463-4185e60b0000 pid=3046 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=4487d59a-1900-0000-6463-4185e60b0000 pid=3046 execve guuid=f82f2a9b-1900-0000-6463-4185e80b0000 pid=3048 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f82f2a9b-1900-0000-6463-4185e80b0000 pid=3048 execve guuid=5e877e9b-1900-0000-6463-4185eb0b0000 pid=3051 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=5e877e9b-1900-0000-6463-4185eb0b0000 pid=3051 execve guuid=8387359c-1900-0000-6463-4185ee0b0000 pid=3054 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=8387359c-1900-0000-6463-4185ee0b0000 pid=3054 execve guuid=c7cbb79c-1900-0000-6463-4185f00b0000 pid=3056 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=c7cbb79c-1900-0000-6463-4185f00b0000 pid=3056 execve guuid=6e31759d-1900-0000-6463-4185f30b0000 pid=3059 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6e31759d-1900-0000-6463-4185f30b0000 pid=3059 execve guuid=20b1019e-1900-0000-6463-4185f60b0000 pid=3062 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=20b1019e-1900-0000-6463-4185f60b0000 pid=3062 execve guuid=6e367b9e-1900-0000-6463-4185f90b0000 pid=3065 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6e367b9e-1900-0000-6463-4185f90b0000 pid=3065 execve guuid=6228f19e-1900-0000-6463-4185fc0b0000 pid=3068 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6228f19e-1900-0000-6463-4185fc0b0000 pid=3068 execve guuid=ca71639f-1900-0000-6463-4185fe0b0000 pid=3070 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=ca71639f-1900-0000-6463-4185fe0b0000 pid=3070 execve guuid=35cbc79f-1900-0000-6463-4185000c0000 pid=3072 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=35cbc79f-1900-0000-6463-4185000c0000 pid=3072 execve guuid=f9db2ba0-1900-0000-6463-4185020c0000 pid=3074 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f9db2ba0-1900-0000-6463-4185020c0000 pid=3074 execve guuid=c4ac97a0-1900-0000-6463-4185050c0000 pid=3077 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=c4ac97a0-1900-0000-6463-4185050c0000 pid=3077 execve guuid=7c3702a1-1900-0000-6463-4185070c0000 pid=3079 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=7c3702a1-1900-0000-6463-4185070c0000 pid=3079 execve guuid=3ecf6fa1-1900-0000-6463-41850a0c0000 pid=3082 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=3ecf6fa1-1900-0000-6463-41850a0c0000 pid=3082 execve guuid=9b0bdda1-1900-0000-6463-41850c0c0000 pid=3084 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=9b0bdda1-1900-0000-6463-41850c0c0000 pid=3084 execve guuid=3f4644a2-1900-0000-6463-41850f0c0000 pid=3087 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=3f4644a2-1900-0000-6463-41850f0c0000 pid=3087 execve guuid=e176a4a2-1900-0000-6463-4185110c0000 pid=3089 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=e176a4a2-1900-0000-6463-4185110c0000 pid=3089 execve guuid=6c0707a3-1900-0000-6463-4185140c0000 pid=3092 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6c0707a3-1900-0000-6463-4185140c0000 pid=3092 execve guuid=dee474a3-1900-0000-6463-4185160c0000 pid=3094 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=dee474a3-1900-0000-6463-4185160c0000 pid=3094 execve guuid=d7b8cfa3-1900-0000-6463-4185180c0000 pid=3096 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=d7b8cfa3-1900-0000-6463-4185180c0000 pid=3096 execve guuid=11082aa4-1900-0000-6463-41851a0c0000 pid=3098 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=11082aa4-1900-0000-6463-41851a0c0000 pid=3098 execve guuid=bffc83a4-1900-0000-6463-41851d0c0000 pid=3101 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=bffc83a4-1900-0000-6463-41851d0c0000 pid=3101 execve guuid=5564e7a4-1900-0000-6463-41851e0c0000 pid=3102 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=5564e7a4-1900-0000-6463-41851e0c0000 pid=3102 execve guuid=85a43da5-1900-0000-6463-4185210c0000 pid=3105 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=85a43da5-1900-0000-6463-4185210c0000 pid=3105 execve guuid=e6779ca5-1900-0000-6463-4185230c0000 pid=3107 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=e6779ca5-1900-0000-6463-4185230c0000 pid=3107 execve guuid=8729fea5-1900-0000-6463-4185250c0000 pid=3109 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=8729fea5-1900-0000-6463-4185250c0000 pid=3109 execve guuid=200d65a6-1900-0000-6463-4185270c0000 pid=3111 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=200d65a6-1900-0000-6463-4185270c0000 pid=3111 execve guuid=e501f9a6-1900-0000-6463-41852a0c0000 pid=3114 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=e501f9a6-1900-0000-6463-41852a0c0000 pid=3114 execve guuid=1ecf63a7-1900-0000-6463-41852d0c0000 pid=3117 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=1ecf63a7-1900-0000-6463-41852d0c0000 pid=3117 execve guuid=0118c6a7-1900-0000-6463-4185300c0000 pid=3120 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=0118c6a7-1900-0000-6463-4185300c0000 pid=3120 execve guuid=89362aa8-1900-0000-6463-4185320c0000 pid=3122 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=89362aa8-1900-0000-6463-4185320c0000 pid=3122 execve guuid=7e2c90a8-1900-0000-6463-4185350c0000 pid=3125 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=7e2c90a8-1900-0000-6463-4185350c0000 pid=3125 execve guuid=c70d09a9-1900-0000-6463-4185370c0000 pid=3127 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=c70d09a9-1900-0000-6463-4185370c0000 pid=3127 execve guuid=6dab6ba9-1900-0000-6463-41853a0c0000 pid=3130 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6dab6ba9-1900-0000-6463-41853a0c0000 pid=3130 execve guuid=10942aaa-1900-0000-6463-41853d0c0000 pid=3133 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=10942aaa-1900-0000-6463-41853d0c0000 pid=3133 execve guuid=3c949caa-1900-0000-6463-4185400c0000 pid=3136 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=3c949caa-1900-0000-6463-4185400c0000 pid=3136 execve guuid=2481ffaa-1900-0000-6463-4185430c0000 pid=3139 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=2481ffaa-1900-0000-6463-4185430c0000 pid=3139 execve guuid=81475bab-1900-0000-6463-4185450c0000 pid=3141 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=81475bab-1900-0000-6463-4185450c0000 pid=3141 execve guuid=669ee8ab-1900-0000-6463-4185480c0000 pid=3144 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=669ee8ab-1900-0000-6463-4185480c0000 pid=3144 execve guuid=528a4eac-1900-0000-6463-41854a0c0000 pid=3146 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=528a4eac-1900-0000-6463-41854a0c0000 pid=3146 execve guuid=7669b9ac-1900-0000-6463-41854c0c0000 pid=3148 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=7669b9ac-1900-0000-6463-41854c0c0000 pid=3148 execve guuid=31c129ad-1900-0000-6463-4185500c0000 pid=3152 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=31c129ad-1900-0000-6463-4185500c0000 pid=3152 execve guuid=0644a2ad-1900-0000-6463-4185510c0000 pid=3153 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=0644a2ad-1900-0000-6463-4185510c0000 pid=3153 execve guuid=e7181fae-1900-0000-6463-4185520c0000 pid=3154 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=e7181fae-1900-0000-6463-4185520c0000 pid=3154 execve guuid=463183ae-1900-0000-6463-4185540c0000 pid=3156 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=463183ae-1900-0000-6463-4185540c0000 pid=3156 execve guuid=efe2e6ae-1900-0000-6463-4185570c0000 pid=3159 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=efe2e6ae-1900-0000-6463-4185570c0000 pid=3159 execve guuid=4a324baf-1900-0000-6463-4185590c0000 pid=3161 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=4a324baf-1900-0000-6463-4185590c0000 pid=3161 execve guuid=60a5acaf-1900-0000-6463-41855c0c0000 pid=3164 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=60a5acaf-1900-0000-6463-41855c0c0000 pid=3164 execve guuid=7df30bb0-1900-0000-6463-41855e0c0000 pid=3166 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=7df30bb0-1900-0000-6463-41855e0c0000 pid=3166 execve guuid=6fd46fb0-1900-0000-6463-4185600c0000 pid=3168 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6fd46fb0-1900-0000-6463-4185600c0000 pid=3168 execve guuid=80292ab1-1900-0000-6463-4185640c0000 pid=3172 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=80292ab1-1900-0000-6463-4185640c0000 pid=3172 execve guuid=6b079cb1-1900-0000-6463-4185660c0000 pid=3174 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=6b079cb1-1900-0000-6463-4185660c0000 pid=3174 execve guuid=4ea006b2-1900-0000-6463-4185670c0000 pid=3175 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=4ea006b2-1900-0000-6463-4185670c0000 pid=3175 execve guuid=f2179ab2-1900-0000-6463-4185680c0000 pid=3176 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f2179ab2-1900-0000-6463-4185680c0000 pid=3176 execve guuid=9fe504b3-1900-0000-6463-4185690c0000 pid=3177 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=9fe504b3-1900-0000-6463-4185690c0000 pid=3177 execve guuid=2755aab3-1900-0000-6463-41856b0c0000 pid=3179 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=2755aab3-1900-0000-6463-41856b0c0000 pid=3179 execve guuid=c6ac7eb4-1900-0000-6463-41856c0c0000 pid=3180 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=c6ac7eb4-1900-0000-6463-41856c0c0000 pid=3180 execve guuid=a8db1bb5-1900-0000-6463-41856f0c0000 pid=3183 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a8db1bb5-1900-0000-6463-41856f0c0000 pid=3183 execve guuid=975aa7b5-1900-0000-6463-4185720c0000 pid=3186 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=975aa7b5-1900-0000-6463-4185720c0000 pid=3186 execve guuid=09e41cb6-1900-0000-6463-4185740c0000 pid=3188 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=09e41cb6-1900-0000-6463-4185740c0000 pid=3188 execve guuid=d84677b6-1900-0000-6463-4185760c0000 pid=3190 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=d84677b6-1900-0000-6463-4185760c0000 pid=3190 execve guuid=04e8e4b6-1900-0000-6463-4185790c0000 pid=3193 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=04e8e4b6-1900-0000-6463-4185790c0000 pid=3193 execve guuid=074a53b7-1900-0000-6463-41857c0c0000 pid=3196 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=074a53b7-1900-0000-6463-41857c0c0000 pid=3196 execve guuid=b0bb04b8-1900-0000-6463-41857e0c0000 pid=3198 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=b0bb04b8-1900-0000-6463-41857e0c0000 pid=3198 execve guuid=819aa1b8-1900-0000-6463-4185800c0000 pid=3200 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=819aa1b8-1900-0000-6463-4185800c0000 pid=3200 execve guuid=b1b96bb9-1900-0000-6463-4185810c0000 pid=3201 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=b1b96bb9-1900-0000-6463-4185810c0000 pid=3201 execve guuid=f5dffbb9-1900-0000-6463-4185830c0000 pid=3203 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f5dffbb9-1900-0000-6463-4185830c0000 pid=3203 execve guuid=128f97ba-1900-0000-6463-4185840c0000 pid=3204 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=128f97ba-1900-0000-6463-4185840c0000 pid=3204 execve guuid=310a19bb-1900-0000-6463-4185850c0000 pid=3205 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=310a19bb-1900-0000-6463-4185850c0000 pid=3205 execve guuid=9e897ebb-1900-0000-6463-4185870c0000 pid=3207 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=9e897ebb-1900-0000-6463-4185870c0000 pid=3207 execve guuid=a4d1dfbb-1900-0000-6463-41858a0c0000 pid=3210 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a4d1dfbb-1900-0000-6463-41858a0c0000 pid=3210 execve guuid=f74148bc-1900-0000-6463-41858c0c0000 pid=3212 /usr/bin/ls guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f74148bc-1900-0000-6463-41858c0c0000 pid=3212 execve guuid=170facbc-1900-0000-6463-41858f0c0000 pid=3215 /usr/bin/rm guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=170facbc-1900-0000-6463-41858f0c0000 pid=3215 execve guuid=3ff729bd-1900-0000-6463-4185920c0000 pid=3218 /usr/bin/wget net send-data write-file guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=3ff729bd-1900-0000-6463-4185920c0000 pid=3218 execve guuid=405d29f9-1900-0000-6463-4185de0c0000 pid=3294 /usr/bin/chmod guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=405d29f9-1900-0000-6463-4185de0c0000 pid=3294 execve guuid=782573f9-1900-0000-6463-4185e00c0000 pid=3296 /usr/bin/dash guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=782573f9-1900-0000-6463-4185e00c0000 pid=3296 clone guuid=a21780fb-1900-0000-6463-4185e20c0000 pid=3298 /usr/bin/rm guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a21780fb-1900-0000-6463-4185e20c0000 pid=3298 execve guuid=ef5ac4fb-1900-0000-6463-4185e30c0000 pid=3299 /usr/bin/wget net send-data write-file guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=ef5ac4fb-1900-0000-6463-4185e30c0000 pid=3299 execve guuid=86a0445f-1a00-0000-6463-4185400d0000 pid=3392 /usr/bin/chmod guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=86a0445f-1a00-0000-6463-4185400d0000 pid=3392 execve guuid=cc77a75f-1a00-0000-6463-4185420d0000 pid=3394 /usr/bin/dash guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=cc77a75f-1a00-0000-6463-4185420d0000 pid=3394 clone guuid=8f27aa61-1a00-0000-6463-4185460d0000 pid=3398 /usr/bin/rm guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=8f27aa61-1a00-0000-6463-4185460d0000 pid=3398 execve guuid=a3e91362-1a00-0000-6463-4185480d0000 pid=3400 /usr/bin/wget net send-data write-file guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a3e91362-1a00-0000-6463-4185480d0000 pid=3400 execve guuid=a91e3eef-1a00-0000-6463-4185290e0000 pid=3625 /usr/bin/chmod guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=a91e3eef-1a00-0000-6463-4185290e0000 pid=3625 execve guuid=e6c6d8ef-1a00-0000-6463-41852c0e0000 pid=3628 /usr/bin/dash guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=e6c6d8ef-1a00-0000-6463-41852c0e0000 pid=3628 clone guuid=96bf89f0-1a00-0000-6463-4185300e0000 pid=3632 /usr/bin/rm guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=96bf89f0-1a00-0000-6463-4185300e0000 pid=3632 execve guuid=95e2c9f0-1a00-0000-6463-4185310e0000 pid=3633 /usr/bin/wget net send-data write-file guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=95e2c9f0-1a00-0000-6463-4185310e0000 pid=3633 execve guuid=df049762-1b00-0000-6463-4185070f0000 pid=3847 /usr/bin/chmod guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=df049762-1b00-0000-6463-4185070f0000 pid=3847 execve guuid=d6eb0663-1b00-0000-6463-4185090f0000 pid=3849 /usr/bin/dash guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=d6eb0663-1b00-0000-6463-4185090f0000 pid=3849 clone guuid=16ddcb63-1b00-0000-6463-41850d0f0000 pid=3853 /usr/bin/rm guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=16ddcb63-1b00-0000-6463-41850d0f0000 pid=3853 execve guuid=f6d91a64-1b00-0000-6463-4185100f0000 pid=3856 /usr/bin/wget net send-data write-file guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=f6d91a64-1b00-0000-6463-4185100f0000 pid=3856 execve guuid=99816aaf-1b00-0000-6463-4185710f0000 pid=3953 /usr/bin/chmod guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=99816aaf-1b00-0000-6463-4185710f0000 pid=3953 execve guuid=7a1a39b0-1b00-0000-6463-4185720f0000 pid=3954 /usr/bin/dash guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=7a1a39b0-1b00-0000-6463-4185720f0000 pid=3954 clone guuid=858c68b1-1b00-0000-6463-4185740f0000 pid=3956 /usr/bin/rm delete-file guuid=b2973686-1900-0000-6463-4185870b0000 pid=2951->guuid=858c68b1-1b00-0000-6463-4185740f0000 pid=3956 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=3ff729bd-1900-0000-6463-4185920c0000 pid=3218->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=ef5ac4fb-1900-0000-6463-4185e30c0000 pid=3299->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=a3e91362-1a00-0000-6463-4185480d0000 pid=3400->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=95e2c9f0-1a00-0000-6463-4185310e0000 pid=3633->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=f6d91a64-1b00-0000-6463-4185100f0000 pid=3856->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-09 20:45:18 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 505341cbb6e1bd79ea2a4816d42441bec8d7d0ab131d37232ea555cb80abeca9

(this sample)

  
Delivery method
Distributed via web download

Comments