MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6fe9ecfd106dae476b08b05cae0f73d9c30bd6468cfefed7461fd1d77ccb6fbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 6fe9ecfd106dae476b08b05cae0f73d9c30bd6468cfefed7461fd1d77ccb6fbb
SHA3-384 hash: 42f1bf5e2373690b031ecdfa4f01ece14b2e901df45eaeefd5057b8d7fb17cfb1afd13b82309b56162dbc503ed319928
SHA1 hash: b2faab6078afb141ef14e89e150071b30c387410
MD5 hash: f523a3a875b85f4041264f3d13fd4bb3
humanhash: alaska-mars-alaska-eighteen
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-09 08:15:42 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkar91INHhQIQPz3lxOIHrsZFIhjBICauD:kXCKysE2hi0ziQvZoharjfnTSaQFGVB7
TLSH T18B01ABDEC05696A0419AE89E239759C07411C3CB6A424FE87EDC543DEBA9308B099F99
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/kEaqn/an/aelf ua-wget
http://188.132.232.81/BFfYn/an/aelf ua-wget
http://188.132.232.81/msjKn/an/aelf ua-wget
http://188.132.232.81/4oEn/an/aelf ua-wget
http://188.132.232.81/iqpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=26f63a5b-7800-0000-3d91-6f4437040000 pid=1079 /usr/bin/sudo guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080 /tmp/sample.bin write-file guuid=26f63a5b-7800-0000-3d91-6f4437040000 pid=1079->guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080 execve guuid=e76fead2-7900-0000-3d91-6f4439040000 pid=1081 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e76fead2-7900-0000-3d91-6f4439040000 pid=1081 execve guuid=6d4ecad3-7900-0000-3d91-6f443a040000 pid=1082 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=6d4ecad3-7900-0000-3d91-6f443a040000 pid=1082 execve guuid=0aa197d4-7900-0000-3d91-6f443b040000 pid=1083 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=0aa197d4-7900-0000-3d91-6f443b040000 pid=1083 execve guuid=2d9cc6d5-7900-0000-3d91-6f443c040000 pid=1084 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=2d9cc6d5-7900-0000-3d91-6f443c040000 pid=1084 execve guuid=3ef0aad6-7900-0000-3d91-6f443d040000 pid=1085 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3ef0aad6-7900-0000-3d91-6f443d040000 pid=1085 execve guuid=7c6d73d7-7900-0000-3d91-6f443e040000 pid=1086 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=7c6d73d7-7900-0000-3d91-6f443e040000 pid=1086 execve guuid=82ae49d8-7900-0000-3d91-6f443f040000 pid=1087 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=82ae49d8-7900-0000-3d91-6f443f040000 pid=1087 execve guuid=b2740ed9-7900-0000-3d91-6f4440040000 pid=1088 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=b2740ed9-7900-0000-3d91-6f4440040000 pid=1088 execve guuid=1ba4b6d9-7900-0000-3d91-6f4441040000 pid=1089 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1ba4b6d9-7900-0000-3d91-6f4441040000 pid=1089 execve guuid=fad72eda-7900-0000-3d91-6f4442040000 pid=1090 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=fad72eda-7900-0000-3d91-6f4442040000 pid=1090 execve guuid=51c5a4da-7900-0000-3d91-6f4443040000 pid=1091 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=51c5a4da-7900-0000-3d91-6f4443040000 pid=1091 execve guuid=173f13db-7900-0000-3d91-6f4444040000 pid=1092 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=173f13db-7900-0000-3d91-6f4444040000 pid=1092 execve guuid=01c074db-7900-0000-3d91-6f4445040000 pid=1093 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=01c074db-7900-0000-3d91-6f4445040000 pid=1093 execve guuid=ed20ccdb-7900-0000-3d91-6f4446040000 pid=1094 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=ed20ccdb-7900-0000-3d91-6f4446040000 pid=1094 execve guuid=872e29dc-7900-0000-3d91-6f4447040000 pid=1095 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=872e29dc-7900-0000-3d91-6f4447040000 pid=1095 execve guuid=e3738adc-7900-0000-3d91-6f4448040000 pid=1096 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e3738adc-7900-0000-3d91-6f4448040000 pid=1096 execve guuid=668cecdc-7900-0000-3d91-6f4449040000 pid=1097 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=668cecdc-7900-0000-3d91-6f4449040000 pid=1097 execve guuid=175054dd-7900-0000-3d91-6f444a040000 pid=1098 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=175054dd-7900-0000-3d91-6f444a040000 pid=1098 execve guuid=5671cddd-7900-0000-3d91-6f444b040000 pid=1099 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5671cddd-7900-0000-3d91-6f444b040000 pid=1099 execve guuid=f23a66de-7900-0000-3d91-6f444c040000 pid=1100 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=f23a66de-7900-0000-3d91-6f444c040000 pid=1100 execve guuid=afa4d4de-7900-0000-3d91-6f444d040000 pid=1101 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=afa4d4de-7900-0000-3d91-6f444d040000 pid=1101 execve guuid=c44878df-7900-0000-3d91-6f444e040000 pid=1102 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c44878df-7900-0000-3d91-6f444e040000 pid=1102 execve guuid=af1411e0-7900-0000-3d91-6f444f040000 pid=1103 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=af1411e0-7900-0000-3d91-6f444f040000 pid=1103 execve guuid=f31c7fe0-7900-0000-3d91-6f4450040000 pid=1104 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=f31c7fe0-7900-0000-3d91-6f4450040000 pid=1104 execve guuid=ba4437e1-7900-0000-3d91-6f4451040000 pid=1105 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=ba4437e1-7900-0000-3d91-6f4451040000 pid=1105 execve guuid=5e7b9fe1-7900-0000-3d91-6f4452040000 pid=1106 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5e7b9fe1-7900-0000-3d91-6f4452040000 pid=1106 execve guuid=26c50ce2-7900-0000-3d91-6f4453040000 pid=1107 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=26c50ce2-7900-0000-3d91-6f4453040000 pid=1107 execve guuid=13dea6e2-7900-0000-3d91-6f4454040000 pid=1108 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=13dea6e2-7900-0000-3d91-6f4454040000 pid=1108 execve guuid=fdcf18e3-7900-0000-3d91-6f4455040000 pid=1109 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=fdcf18e3-7900-0000-3d91-6f4455040000 pid=1109 execve guuid=94e8dae3-7900-0000-3d91-6f4456040000 pid=1110 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=94e8dae3-7900-0000-3d91-6f4456040000 pid=1110 execve guuid=d04d9ce4-7900-0000-3d91-6f4457040000 pid=1111 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d04d9ce4-7900-0000-3d91-6f4457040000 pid=1111 execve guuid=8fd85fe5-7900-0000-3d91-6f4458040000 pid=1112 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=8fd85fe5-7900-0000-3d91-6f4458040000 pid=1112 execve guuid=ef3c53e6-7900-0000-3d91-6f4459040000 pid=1113 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=ef3c53e6-7900-0000-3d91-6f4459040000 pid=1113 execve guuid=df433be7-7900-0000-3d91-6f445a040000 pid=1114 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=df433be7-7900-0000-3d91-6f445a040000 pid=1114 execve guuid=5e85d3e7-7900-0000-3d91-6f445b040000 pid=1115 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5e85d3e7-7900-0000-3d91-6f445b040000 pid=1115 execve guuid=e92aa8e8-7900-0000-3d91-6f445c040000 pid=1116 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e92aa8e8-7900-0000-3d91-6f445c040000 pid=1116 execve guuid=c8bf42e9-7900-0000-3d91-6f445d040000 pid=1117 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c8bf42e9-7900-0000-3d91-6f445d040000 pid=1117 execve guuid=1eba09ea-7900-0000-3d91-6f445e040000 pid=1118 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1eba09ea-7900-0000-3d91-6f445e040000 pid=1118 execve guuid=553fc2ea-7900-0000-3d91-6f445f040000 pid=1119 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=553fc2ea-7900-0000-3d91-6f445f040000 pid=1119 execve guuid=d8c375eb-7900-0000-3d91-6f4460040000 pid=1120 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d8c375eb-7900-0000-3d91-6f4460040000 pid=1120 execve guuid=ca7239ec-7900-0000-3d91-6f4461040000 pid=1121 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=ca7239ec-7900-0000-3d91-6f4461040000 pid=1121 execve guuid=5f1909ed-7900-0000-3d91-6f4462040000 pid=1122 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5f1909ed-7900-0000-3d91-6f4462040000 pid=1122 execve guuid=3948eced-7900-0000-3d91-6f4463040000 pid=1123 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3948eced-7900-0000-3d91-6f4463040000 pid=1123 execve guuid=13c6d8ee-7900-0000-3d91-6f4464040000 pid=1124 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=13c6d8ee-7900-0000-3d91-6f4464040000 pid=1124 execve guuid=1df1a2ef-7900-0000-3d91-6f4465040000 pid=1125 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1df1a2ef-7900-0000-3d91-6f4465040000 pid=1125 execve guuid=16d695f0-7900-0000-3d91-6f4466040000 pid=1126 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=16d695f0-7900-0000-3d91-6f4466040000 pid=1126 execve guuid=674880f1-7900-0000-3d91-6f4467040000 pid=1127 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=674880f1-7900-0000-3d91-6f4467040000 pid=1127 execve guuid=5c7d54f2-7900-0000-3d91-6f4468040000 pid=1128 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5c7d54f2-7900-0000-3d91-6f4468040000 pid=1128 execve guuid=c8fe13f3-7900-0000-3d91-6f4469040000 pid=1129 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c8fe13f3-7900-0000-3d91-6f4469040000 pid=1129 execve guuid=09c9e8f3-7900-0000-3d91-6f446a040000 pid=1130 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=09c9e8f3-7900-0000-3d91-6f446a040000 pid=1130 execve guuid=f276bff4-7900-0000-3d91-6f446b040000 pid=1131 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=f276bff4-7900-0000-3d91-6f446b040000 pid=1131 execve guuid=a39f9df5-7900-0000-3d91-6f446c040000 pid=1132 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=a39f9df5-7900-0000-3d91-6f446c040000 pid=1132 execve guuid=33078bf6-7900-0000-3d91-6f446d040000 pid=1133 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=33078bf6-7900-0000-3d91-6f446d040000 pid=1133 execve guuid=240e72f7-7900-0000-3d91-6f446e040000 pid=1134 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=240e72f7-7900-0000-3d91-6f446e040000 pid=1134 execve guuid=3f973df8-7900-0000-3d91-6f446f040000 pid=1135 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3f973df8-7900-0000-3d91-6f446f040000 pid=1135 execve guuid=d32919f9-7900-0000-3d91-6f4470040000 pid=1136 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d32919f9-7900-0000-3d91-6f4470040000 pid=1136 execve guuid=9aa0ddf9-7900-0000-3d91-6f4471040000 pid=1137 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=9aa0ddf9-7900-0000-3d91-6f4471040000 pid=1137 execve guuid=92e7ccfa-7900-0000-3d91-6f4472040000 pid=1138 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=92e7ccfa-7900-0000-3d91-6f4472040000 pid=1138 execve guuid=9c8aa8fb-7900-0000-3d91-6f4473040000 pid=1139 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=9c8aa8fb-7900-0000-3d91-6f4473040000 pid=1139 execve guuid=552f87fc-7900-0000-3d91-6f4474040000 pid=1140 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=552f87fc-7900-0000-3d91-6f4474040000 pid=1140 execve guuid=459f5bfd-7900-0000-3d91-6f4475040000 pid=1141 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=459f5bfd-7900-0000-3d91-6f4475040000 pid=1141 execve guuid=412e41fe-7900-0000-3d91-6f4476040000 pid=1142 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=412e41fe-7900-0000-3d91-6f4476040000 pid=1142 execve guuid=82f802ff-7900-0000-3d91-6f4477040000 pid=1143 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=82f802ff-7900-0000-3d91-6f4477040000 pid=1143 execve guuid=fc2bd4ff-7900-0000-3d91-6f4478040000 pid=1144 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=fc2bd4ff-7900-0000-3d91-6f4478040000 pid=1144 execve guuid=d426aa00-7a00-0000-3d91-6f4479040000 pid=1145 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d426aa00-7a00-0000-3d91-6f4479040000 pid=1145 execve guuid=6f4f9401-7a00-0000-3d91-6f447a040000 pid=1146 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=6f4f9401-7a00-0000-3d91-6f447a040000 pid=1146 execve guuid=7fdb6c02-7a00-0000-3d91-6f447b040000 pid=1147 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=7fdb6c02-7a00-0000-3d91-6f447b040000 pid=1147 execve guuid=446f5b03-7a00-0000-3d91-6f447c040000 pid=1148 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=446f5b03-7a00-0000-3d91-6f447c040000 pid=1148 execve guuid=05e13404-7a00-0000-3d91-6f447d040000 pid=1149 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=05e13404-7a00-0000-3d91-6f447d040000 pid=1149 execve guuid=ede6f404-7a00-0000-3d91-6f447e040000 pid=1150 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=ede6f404-7a00-0000-3d91-6f447e040000 pid=1150 execve guuid=0ac8e405-7a00-0000-3d91-6f447f040000 pid=1151 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=0ac8e405-7a00-0000-3d91-6f447f040000 pid=1151 execve guuid=50b0c306-7a00-0000-3d91-6f4480040000 pid=1152 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=50b0c306-7a00-0000-3d91-6f4480040000 pid=1152 execve guuid=36d89607-7a00-0000-3d91-6f4481040000 pid=1153 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=36d89607-7a00-0000-3d91-6f4481040000 pid=1153 execve guuid=433c8a08-7a00-0000-3d91-6f4482040000 pid=1154 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=433c8a08-7a00-0000-3d91-6f4482040000 pid=1154 execve guuid=45a35c09-7a00-0000-3d91-6f4483040000 pid=1155 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=45a35c09-7a00-0000-3d91-6f4483040000 pid=1155 execve guuid=e6aa420a-7a00-0000-3d91-6f4484040000 pid=1156 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e6aa420a-7a00-0000-3d91-6f4484040000 pid=1156 execve guuid=5240ff0a-7a00-0000-3d91-6f4485040000 pid=1157 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5240ff0a-7a00-0000-3d91-6f4485040000 pid=1157 execve guuid=8cd5f60b-7a00-0000-3d91-6f4486040000 pid=1158 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=8cd5f60b-7a00-0000-3d91-6f4486040000 pid=1158 execve guuid=4df5d10c-7a00-0000-3d91-6f4487040000 pid=1159 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=4df5d10c-7a00-0000-3d91-6f4487040000 pid=1159 execve guuid=2dfebe0d-7a00-0000-3d91-6f4488040000 pid=1160 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=2dfebe0d-7a00-0000-3d91-6f4488040000 pid=1160 execve guuid=d4779e0e-7a00-0000-3d91-6f4489040000 pid=1161 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d4779e0e-7a00-0000-3d91-6f4489040000 pid=1161 execve guuid=3fd1890f-7a00-0000-3d91-6f448a040000 pid=1162 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3fd1890f-7a00-0000-3d91-6f448a040000 pid=1162 execve guuid=fea76710-7a00-0000-3d91-6f448b040000 pid=1163 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=fea76710-7a00-0000-3d91-6f448b040000 pid=1163 execve guuid=c26c3811-7a00-0000-3d91-6f448c040000 pid=1164 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c26c3811-7a00-0000-3d91-6f448c040000 pid=1164 execve guuid=96c81112-7a00-0000-3d91-6f448d040000 pid=1165 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=96c81112-7a00-0000-3d91-6f448d040000 pid=1165 execve guuid=1a790513-7a00-0000-3d91-6f448e040000 pid=1166 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1a790513-7a00-0000-3d91-6f448e040000 pid=1166 execve guuid=e716e013-7a00-0000-3d91-6f448f040000 pid=1167 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e716e013-7a00-0000-3d91-6f448f040000 pid=1167 execve guuid=a561c914-7a00-0000-3d91-6f4490040000 pid=1168 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=a561c914-7a00-0000-3d91-6f4490040000 pid=1168 execve guuid=6e2baf15-7a00-0000-3d91-6f4491040000 pid=1169 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=6e2baf15-7a00-0000-3d91-6f4491040000 pid=1169 execve guuid=2ced7c16-7a00-0000-3d91-6f4492040000 pid=1170 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=2ced7c16-7a00-0000-3d91-6f4492040000 pid=1170 execve guuid=c9886717-7a00-0000-3d91-6f4493040000 pid=1171 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c9886717-7a00-0000-3d91-6f4493040000 pid=1171 execve guuid=d8214418-7a00-0000-3d91-6f4494040000 pid=1172 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d8214418-7a00-0000-3d91-6f4494040000 pid=1172 execve guuid=0cde2219-7a00-0000-3d91-6f4495040000 pid=1173 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=0cde2219-7a00-0000-3d91-6f4495040000 pid=1173 execve guuid=7a6aef19-7a00-0000-3d91-6f4496040000 pid=1174 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=7a6aef19-7a00-0000-3d91-6f4496040000 pid=1174 execve guuid=1aefc81a-7a00-0000-3d91-6f4497040000 pid=1175 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1aefc81a-7a00-0000-3d91-6f4497040000 pid=1175 execve guuid=3fdeaf1b-7a00-0000-3d91-6f4498040000 pid=1176 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3fdeaf1b-7a00-0000-3d91-6f4498040000 pid=1176 execve guuid=3382851c-7a00-0000-3d91-6f4499040000 pid=1177 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3382851c-7a00-0000-3d91-6f4499040000 pid=1177 execve guuid=87bc5b1d-7a00-0000-3d91-6f449a040000 pid=1178 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=87bc5b1d-7a00-0000-3d91-6f449a040000 pid=1178 execve guuid=d42b3b1e-7a00-0000-3d91-6f449b040000 pid=1179 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d42b3b1e-7a00-0000-3d91-6f449b040000 pid=1179 execve guuid=423a0a1f-7a00-0000-3d91-6f449c040000 pid=1180 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=423a0a1f-7a00-0000-3d91-6f449c040000 pid=1180 execve guuid=c981f91f-7a00-0000-3d91-6f449d040000 pid=1181 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c981f91f-7a00-0000-3d91-6f449d040000 pid=1181 execve guuid=dc00df20-7a00-0000-3d91-6f449e040000 pid=1182 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=dc00df20-7a00-0000-3d91-6f449e040000 pid=1182 execve guuid=bcb0cd21-7a00-0000-3d91-6f449f040000 pid=1183 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=bcb0cd21-7a00-0000-3d91-6f449f040000 pid=1183 execve guuid=c3389722-7a00-0000-3d91-6f44a0040000 pid=1184 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c3389722-7a00-0000-3d91-6f44a0040000 pid=1184 execve guuid=98b87d23-7a00-0000-3d91-6f44a1040000 pid=1185 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=98b87d23-7a00-0000-3d91-6f44a1040000 pid=1185 execve guuid=deaf5024-7a00-0000-3d91-6f44a2040000 pid=1186 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=deaf5024-7a00-0000-3d91-6f44a2040000 pid=1186 execve guuid=50f94725-7a00-0000-3d91-6f44a3040000 pid=1187 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=50f94725-7a00-0000-3d91-6f44a3040000 pid=1187 execve guuid=81b31a26-7a00-0000-3d91-6f44a4040000 pid=1188 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=81b31a26-7a00-0000-3d91-6f44a4040000 pid=1188 execve guuid=1d5a0327-7a00-0000-3d91-6f44a5040000 pid=1189 /usr/bin/ls guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1d5a0327-7a00-0000-3d91-6f44a5040000 pid=1189 execve guuid=4e32e527-7a00-0000-3d91-6f44a6040000 pid=1190 /usr/bin/rm guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=4e32e527-7a00-0000-3d91-6f44a6040000 pid=1190 execve guuid=d2fc7b28-7a00-0000-3d91-6f44a7040000 pid=1191 /usr/bin/wget net send-data write-file guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=d2fc7b28-7a00-0000-3d91-6f44a7040000 pid=1191 execve guuid=14948027-7b00-0000-3d91-6f44a8040000 pid=1192 /usr/bin/chmod guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=14948027-7b00-0000-3d91-6f44a8040000 pid=1192 execve guuid=c60dc827-7b00-0000-3d91-6f44a9040000 pid=1193 /tmp/kEaq guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c60dc827-7b00-0000-3d91-6f44a9040000 pid=1193 execve guuid=1cfd8b28-7b00-0000-3d91-6f44ab040000 pid=1195 /usr/bin/rm guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=1cfd8b28-7b00-0000-3d91-6f44ab040000 pid=1195 execve guuid=5501c728-7b00-0000-3d91-6f44ac040000 pid=1196 /usr/bin/wget net send-data write-file guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=5501c728-7b00-0000-3d91-6f44ac040000 pid=1196 execve guuid=e8123d2f-7b00-0000-3d91-6f44ad040000 pid=1197 /usr/bin/chmod guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e8123d2f-7b00-0000-3d91-6f44ad040000 pid=1197 execve guuid=14cfb32f-7b00-0000-3d91-6f44ae040000 pid=1198 /tmp/BFfY guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=14cfb32f-7b00-0000-3d91-6f44ae040000 pid=1198 execve guuid=f709dd30-7b00-0000-3d91-6f44b0040000 pid=1200 /usr/bin/rm guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=f709dd30-7b00-0000-3d91-6f44b0040000 pid=1200 execve guuid=85cd4f31-7b00-0000-3d91-6f44b1040000 pid=1201 /usr/bin/wget net send-data write-file guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=85cd4f31-7b00-0000-3d91-6f44b1040000 pid=1201 execve guuid=a3fef146-7b00-0000-3d91-6f44b2040000 pid=1202 /usr/bin/chmod guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=a3fef146-7b00-0000-3d91-6f44b2040000 pid=1202 execve guuid=c7668947-7b00-0000-3d91-6f44b3040000 pid=1203 /tmp/msjK guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=c7668947-7b00-0000-3d91-6f44b3040000 pid=1203 execve guuid=288bf048-7b00-0000-3d91-6f44b5040000 pid=1205 /usr/bin/rm guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=288bf048-7b00-0000-3d91-6f44b5040000 pid=1205 execve guuid=f51a7949-7b00-0000-3d91-6f44b6040000 pid=1206 /usr/bin/wget net send-data write-file guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=f51a7949-7b00-0000-3d91-6f44b6040000 pid=1206 execve guuid=3552ad5e-7b00-0000-3d91-6f44b7040000 pid=1207 /usr/bin/chmod guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=3552ad5e-7b00-0000-3d91-6f44b7040000 pid=1207 execve guuid=54c2315f-7b00-0000-3d91-6f44b8040000 pid=1208 /tmp/4oE guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=54c2315f-7b00-0000-3d91-6f44b8040000 pid=1208 execve guuid=2815d960-7b00-0000-3d91-6f44ba040000 pid=1210 /usr/bin/rm guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=2815d960-7b00-0000-3d91-6f44ba040000 pid=1210 execve guuid=929d5e61-7b00-0000-3d91-6f44bb040000 pid=1211 /usr/bin/wget net send-data write-file guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=929d5e61-7b00-0000-3d91-6f44bb040000 pid=1211 execve guuid=9f842ea9-7b00-0000-3d91-6f44bc040000 pid=1212 /usr/bin/chmod guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=9f842ea9-7b00-0000-3d91-6f44bc040000 pid=1212 execve guuid=e50979a9-7b00-0000-3d91-6f44bd040000 pid=1213 /tmp/iqp guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=e50979a9-7b00-0000-3d91-6f44bd040000 pid=1213 execve guuid=fc3d52aa-7b00-0000-3d91-6f44bf040000 pid=1215 /usr/bin/rm delete-file guuid=1765dc5d-7800-0000-3d91-6f4438040000 pid=1080->guuid=fc3d52aa-7b00-0000-3d91-6f44bf040000 pid=1215 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=d2fc7b28-7a00-0000-3d91-6f44a7040000 pid=1191->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=5501c728-7b00-0000-3d91-6f44ac040000 pid=1196->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=85cd4f31-7b00-0000-3d91-6f44b1040000 pid=1201->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=f51a7949-7b00-0000-3d91-6f44b6040000 pid=1206->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=929d5e61-7b00-0000-3d91-6f44bb040000 pid=1211->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-09 08:16:43 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6fe9ecfd106dae476b08b05cae0f73d9c30bd6468cfefed7461fd1d77ccb6fbb

(this sample)

  
Delivery method
Distributed via web download

Comments