MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7681e29bcb8b6f448cf99cff2c25ae3fa76cde3e67bd36681280ea333fa20636. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 7681e29bcb8b6f448cf99cff2c25ae3fa76cde3e67bd36681280ea333fa20636
SHA3-384 hash: af26a6c7d7ce1938dbbc77ad66f000043191b7b950c4a1b175b2fe4c9df408a7a7eb9c1e465e520b812f3b4c78c448c2
SHA1 hash: c13d1ffc977a86b02af4bbc44551db5b42c280df
MD5 hash: 30255faac4b30ca2df688f244f358529
humanhash: uncle-missouri-pip-undress
File name:p
Download: download sample
File size:830 bytes
First seen:2026-06-03 01:35:42 UTC
Last seen:2026-06-03 18:40:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaITWtjTvbSVMFRr7:e9Qp+MsITWZvOKRr7
TLSH T1FE01CECAC112D75040D5E89E22EBB280B820C3DB19418FF87EDC043EDBA9748B069F98
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/47Hn/an/aelf ua-wget
http://188.132.232.81/m1Ajn/an/aelf ua-wget
http://188.132.232.81/clZOn/an/aelf ua-wget
http://188.132.232.81/RZvn/an/aelf ua-wget
http://188.132.232.81/sP9n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c9e33998-1800-0000-d05e-f2d2ff0c0000 pid=3327 /usr/bin/sudo guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333 /tmp/sample.bin write-file guuid=c9e33998-1800-0000-d05e-f2d2ff0c0000 pid=3327->guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333 execve guuid=e397459a-1800-0000-d05e-f2d2060d0000 pid=3334 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e397459a-1800-0000-d05e-f2d2060d0000 pid=3334 execve guuid=447e0d9b-1800-0000-d05e-f2d2090d0000 pid=3337 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=447e0d9b-1800-0000-d05e-f2d2090d0000 pid=3337 execve guuid=3cdd6d9b-1800-0000-d05e-f2d20b0d0000 pid=3339 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=3cdd6d9b-1800-0000-d05e-f2d20b0d0000 pid=3339 execve guuid=2980d09b-1800-0000-d05e-f2d20e0d0000 pid=3342 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=2980d09b-1800-0000-d05e-f2d20e0d0000 pid=3342 execve guuid=d488349c-1800-0000-d05e-f2d2100d0000 pid=3344 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=d488349c-1800-0000-d05e-f2d2100d0000 pid=3344 execve guuid=f99a9f9c-1800-0000-d05e-f2d2120d0000 pid=3346 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=f99a9f9c-1800-0000-d05e-f2d2120d0000 pid=3346 execve guuid=b126119d-1800-0000-d05e-f2d2130d0000 pid=3347 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=b126119d-1800-0000-d05e-f2d2130d0000 pid=3347 execve guuid=e544819d-1800-0000-d05e-f2d2160d0000 pid=3350 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e544819d-1800-0000-d05e-f2d2160d0000 pid=3350 execve guuid=0f59e79d-1800-0000-d05e-f2d2180d0000 pid=3352 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=0f59e79d-1800-0000-d05e-f2d2180d0000 pid=3352 execve guuid=ec2c4d9e-1800-0000-d05e-f2d21a0d0000 pid=3354 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ec2c4d9e-1800-0000-d05e-f2d21a0d0000 pid=3354 execve guuid=4446af9e-1800-0000-d05e-f2d21c0d0000 pid=3356 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=4446af9e-1800-0000-d05e-f2d21c0d0000 pid=3356 execve guuid=d4e80d9f-1800-0000-d05e-f2d21e0d0000 pid=3358 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=d4e80d9f-1800-0000-d05e-f2d21e0d0000 pid=3358 execve guuid=65dd769f-1800-0000-d05e-f2d2200d0000 pid=3360 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=65dd769f-1800-0000-d05e-f2d2200d0000 pid=3360 execve guuid=8f08f99f-1800-0000-d05e-f2d2210d0000 pid=3361 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=8f08f99f-1800-0000-d05e-f2d2210d0000 pid=3361 execve guuid=10087ea0-1800-0000-d05e-f2d2220d0000 pid=3362 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=10087ea0-1800-0000-d05e-f2d2220d0000 pid=3362 execve guuid=9329eaa0-1800-0000-d05e-f2d2250d0000 pid=3365 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=9329eaa0-1800-0000-d05e-f2d2250d0000 pid=3365 execve guuid=8aa953a1-1800-0000-d05e-f2d2270d0000 pid=3367 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=8aa953a1-1800-0000-d05e-f2d2270d0000 pid=3367 execve guuid=6d53bfa1-1800-0000-d05e-f2d22a0d0000 pid=3370 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=6d53bfa1-1800-0000-d05e-f2d22a0d0000 pid=3370 execve guuid=c28d1ea2-1800-0000-d05e-f2d22c0d0000 pid=3372 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=c28d1ea2-1800-0000-d05e-f2d22c0d0000 pid=3372 execve guuid=e3b581a2-1800-0000-d05e-f2d22e0d0000 pid=3374 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e3b581a2-1800-0000-d05e-f2d22e0d0000 pid=3374 execve guuid=e013eca2-1800-0000-d05e-f2d2300d0000 pid=3376 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e013eca2-1800-0000-d05e-f2d2300d0000 pid=3376 execve guuid=cf5457a3-1800-0000-d05e-f2d2320d0000 pid=3378 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=cf5457a3-1800-0000-d05e-f2d2320d0000 pid=3378 execve guuid=002ec0a3-1800-0000-d05e-f2d2340d0000 pid=3380 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=002ec0a3-1800-0000-d05e-f2d2340d0000 pid=3380 execve guuid=0c862aa4-1800-0000-d05e-f2d2360d0000 pid=3382 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=0c862aa4-1800-0000-d05e-f2d2360d0000 pid=3382 execve guuid=e5caaca4-1800-0000-d05e-f2d2370d0000 pid=3383 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e5caaca4-1800-0000-d05e-f2d2370d0000 pid=3383 execve guuid=761643a5-1800-0000-d05e-f2d2380d0000 pid=3384 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=761643a5-1800-0000-d05e-f2d2380d0000 pid=3384 execve guuid=a4a7d9a5-1800-0000-d05e-f2d2390d0000 pid=3385 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=a4a7d9a5-1800-0000-d05e-f2d2390d0000 pid=3385 execve guuid=06dd4ba6-1800-0000-d05e-f2d23b0d0000 pid=3387 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=06dd4ba6-1800-0000-d05e-f2d23b0d0000 pid=3387 execve guuid=bc42b2a6-1800-0000-d05e-f2d23d0d0000 pid=3389 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=bc42b2a6-1800-0000-d05e-f2d23d0d0000 pid=3389 execve guuid=84e714a7-1800-0000-d05e-f2d2400d0000 pid=3392 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=84e714a7-1800-0000-d05e-f2d2400d0000 pid=3392 execve guuid=3a0079a7-1800-0000-d05e-f2d2420d0000 pid=3394 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=3a0079a7-1800-0000-d05e-f2d2420d0000 pid=3394 execve guuid=2760dba7-1800-0000-d05e-f2d2440d0000 pid=3396 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=2760dba7-1800-0000-d05e-f2d2440d0000 pid=3396 execve guuid=239e3ba8-1800-0000-d05e-f2d2460d0000 pid=3398 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=239e3ba8-1800-0000-d05e-f2d2460d0000 pid=3398 execve guuid=6eb69aa8-1800-0000-d05e-f2d2480d0000 pid=3400 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=6eb69aa8-1800-0000-d05e-f2d2480d0000 pid=3400 execve guuid=261f05a9-1800-0000-d05e-f2d24a0d0000 pid=3402 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=261f05a9-1800-0000-d05e-f2d24a0d0000 pid=3402 execve guuid=edfbaba9-1800-0000-d05e-f2d24b0d0000 pid=3403 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=edfbaba9-1800-0000-d05e-f2d24b0d0000 pid=3403 execve guuid=23dd4eaa-1800-0000-d05e-f2d24d0d0000 pid=3405 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=23dd4eaa-1800-0000-d05e-f2d24d0d0000 pid=3405 execve guuid=cafcdbaa-1800-0000-d05e-f2d2500d0000 pid=3408 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=cafcdbaa-1800-0000-d05e-f2d2500d0000 pid=3408 execve guuid=e6b58cab-1800-0000-d05e-f2d2530d0000 pid=3411 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e6b58cab-1800-0000-d05e-f2d2530d0000 pid=3411 execve guuid=1f6911ac-1800-0000-d05e-f2d2560d0000 pid=3414 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=1f6911ac-1800-0000-d05e-f2d2560d0000 pid=3414 execve guuid=ba5f86ac-1800-0000-d05e-f2d2590d0000 pid=3417 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ba5f86ac-1800-0000-d05e-f2d2590d0000 pid=3417 execve guuid=ff59f9ac-1800-0000-d05e-f2d25b0d0000 pid=3419 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ff59f9ac-1800-0000-d05e-f2d25b0d0000 pid=3419 execve guuid=108d84ad-1800-0000-d05e-f2d25d0d0000 pid=3421 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=108d84ad-1800-0000-d05e-f2d25d0d0000 pid=3421 execve guuid=671326ae-1800-0000-d05e-f2d2600d0000 pid=3424 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=671326ae-1800-0000-d05e-f2d2600d0000 pid=3424 execve guuid=e192b1ae-1800-0000-d05e-f2d2630d0000 pid=3427 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e192b1ae-1800-0000-d05e-f2d2630d0000 pid=3427 execve guuid=fee34faf-1800-0000-d05e-f2d2650d0000 pid=3429 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=fee34faf-1800-0000-d05e-f2d2650d0000 pid=3429 execve guuid=18dec5af-1800-0000-d05e-f2d2670d0000 pid=3431 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=18dec5af-1800-0000-d05e-f2d2670d0000 pid=3431 execve guuid=fd094cb0-1800-0000-d05e-f2d2690d0000 pid=3433 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=fd094cb0-1800-0000-d05e-f2d2690d0000 pid=3433 execve guuid=2a7fa6b0-1800-0000-d05e-f2d26a0d0000 pid=3434 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=2a7fa6b0-1800-0000-d05e-f2d26a0d0000 pid=3434 execve guuid=8af33db1-1800-0000-d05e-f2d26e0d0000 pid=3438 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=8af33db1-1800-0000-d05e-f2d26e0d0000 pid=3438 execve guuid=c9f994b1-1800-0000-d05e-f2d2700d0000 pid=3440 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=c9f994b1-1800-0000-d05e-f2d2700d0000 pid=3440 execve guuid=9c27e1b1-1800-0000-d05e-f2d2720d0000 pid=3442 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=9c27e1b1-1800-0000-d05e-f2d2720d0000 pid=3442 execve guuid=096635b2-1800-0000-d05e-f2d2740d0000 pid=3444 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=096635b2-1800-0000-d05e-f2d2740d0000 pid=3444 execve guuid=8d5c89b2-1800-0000-d05e-f2d2760d0000 pid=3446 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=8d5c89b2-1800-0000-d05e-f2d2760d0000 pid=3446 execve guuid=919dfcb2-1800-0000-d05e-f2d2790d0000 pid=3449 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=919dfcb2-1800-0000-d05e-f2d2790d0000 pid=3449 execve guuid=f7ec53b3-1800-0000-d05e-f2d27c0d0000 pid=3452 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=f7ec53b3-1800-0000-d05e-f2d27c0d0000 pid=3452 execve guuid=b309b1b3-1800-0000-d05e-f2d27e0d0000 pid=3454 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=b309b1b3-1800-0000-d05e-f2d27e0d0000 pid=3454 execve guuid=b6aa06b4-1800-0000-d05e-f2d27f0d0000 pid=3455 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=b6aa06b4-1800-0000-d05e-f2d27f0d0000 pid=3455 execve guuid=282562b4-1800-0000-d05e-f2d2810d0000 pid=3457 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=282562b4-1800-0000-d05e-f2d2810d0000 pid=3457 execve guuid=b06fd9b4-1800-0000-d05e-f2d2840d0000 pid=3460 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=b06fd9b4-1800-0000-d05e-f2d2840d0000 pid=3460 execve guuid=f13967b5-1800-0000-d05e-f2d2870d0000 pid=3463 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=f13967b5-1800-0000-d05e-f2d2870d0000 pid=3463 execve guuid=cf16dfb5-1800-0000-d05e-f2d28a0d0000 pid=3466 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=cf16dfb5-1800-0000-d05e-f2d28a0d0000 pid=3466 execve guuid=a8f53fb6-1800-0000-d05e-f2d28c0d0000 pid=3468 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=a8f53fb6-1800-0000-d05e-f2d28c0d0000 pid=3468 execve guuid=24bba5b6-1800-0000-d05e-f2d28e0d0000 pid=3470 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=24bba5b6-1800-0000-d05e-f2d28e0d0000 pid=3470 execve guuid=af4f12b7-1800-0000-d05e-f2d2900d0000 pid=3472 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=af4f12b7-1800-0000-d05e-f2d2900d0000 pid=3472 execve guuid=ec5077b7-1800-0000-d05e-f2d2920d0000 pid=3474 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ec5077b7-1800-0000-d05e-f2d2920d0000 pid=3474 execve guuid=8db1dbb7-1800-0000-d05e-f2d2940d0000 pid=3476 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=8db1dbb7-1800-0000-d05e-f2d2940d0000 pid=3476 execve guuid=9deb3bb8-1800-0000-d05e-f2d2960d0000 pid=3478 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=9deb3bb8-1800-0000-d05e-f2d2960d0000 pid=3478 execve guuid=ebea9cb8-1800-0000-d05e-f2d2980d0000 pid=3480 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ebea9cb8-1800-0000-d05e-f2d2980d0000 pid=3480 execve guuid=6fe8fcb8-1800-0000-d05e-f2d29a0d0000 pid=3482 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=6fe8fcb8-1800-0000-d05e-f2d29a0d0000 pid=3482 execve guuid=bb3c5cb9-1800-0000-d05e-f2d29c0d0000 pid=3484 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=bb3c5cb9-1800-0000-d05e-f2d29c0d0000 pid=3484 execve guuid=ac4ecab9-1800-0000-d05e-f2d29f0d0000 pid=3487 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ac4ecab9-1800-0000-d05e-f2d29f0d0000 pid=3487 execve guuid=9dba24ba-1800-0000-d05e-f2d2a00d0000 pid=3488 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=9dba24ba-1800-0000-d05e-f2d2a00d0000 pid=3488 execve guuid=39ced7ba-1800-0000-d05e-f2d2a40d0000 pid=3492 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=39ced7ba-1800-0000-d05e-f2d2a40d0000 pid=3492 execve guuid=36e176bb-1800-0000-d05e-f2d2a80d0000 pid=3496 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=36e176bb-1800-0000-d05e-f2d2a80d0000 pid=3496 execve guuid=e3aecdbb-1800-0000-d05e-f2d2aa0d0000 pid=3498 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e3aecdbb-1800-0000-d05e-f2d2aa0d0000 pid=3498 execve guuid=49b82cbc-1800-0000-d05e-f2d2ac0d0000 pid=3500 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=49b82cbc-1800-0000-d05e-f2d2ac0d0000 pid=3500 execve guuid=3cec86bc-1800-0000-d05e-f2d2af0d0000 pid=3503 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=3cec86bc-1800-0000-d05e-f2d2af0d0000 pid=3503 execve guuid=3bcde3bc-1800-0000-d05e-f2d2b10d0000 pid=3505 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=3bcde3bc-1800-0000-d05e-f2d2b10d0000 pid=3505 execve guuid=76473fbd-1800-0000-d05e-f2d2b30d0000 pid=3507 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=76473fbd-1800-0000-d05e-f2d2b30d0000 pid=3507 execve guuid=a1f3a8bd-1800-0000-d05e-f2d2b60d0000 pid=3510 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=a1f3a8bd-1800-0000-d05e-f2d2b60d0000 pid=3510 execve guuid=eece15be-1800-0000-d05e-f2d2b80d0000 pid=3512 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=eece15be-1800-0000-d05e-f2d2b80d0000 pid=3512 execve guuid=846c70be-1800-0000-d05e-f2d2bb0d0000 pid=3515 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=846c70be-1800-0000-d05e-f2d2bb0d0000 pid=3515 execve guuid=7242c8be-1800-0000-d05e-f2d2bd0d0000 pid=3517 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=7242c8be-1800-0000-d05e-f2d2bd0d0000 pid=3517 execve guuid=b5b032bf-1800-0000-d05e-f2d2bf0d0000 pid=3519 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=b5b032bf-1800-0000-d05e-f2d2bf0d0000 pid=3519 execve guuid=53edc0bf-1800-0000-d05e-f2d2c20d0000 pid=3522 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=53edc0bf-1800-0000-d05e-f2d2c20d0000 pid=3522 execve guuid=24622fc0-1800-0000-d05e-f2d2c40d0000 pid=3524 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=24622fc0-1800-0000-d05e-f2d2c40d0000 pid=3524 execve guuid=70bf9cc0-1800-0000-d05e-f2d2c50d0000 pid=3525 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=70bf9cc0-1800-0000-d05e-f2d2c50d0000 pid=3525 execve guuid=e8a10bc1-1800-0000-d05e-f2d2c70d0000 pid=3527 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e8a10bc1-1800-0000-d05e-f2d2c70d0000 pid=3527 execve guuid=6b9a77c1-1800-0000-d05e-f2d2c90d0000 pid=3529 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=6b9a77c1-1800-0000-d05e-f2d2c90d0000 pid=3529 execve guuid=f4aadfc1-1800-0000-d05e-f2d2cc0d0000 pid=3532 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=f4aadfc1-1800-0000-d05e-f2d2cc0d0000 pid=3532 execve guuid=e11364c2-1800-0000-d05e-f2d2cf0d0000 pid=3535 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e11364c2-1800-0000-d05e-f2d2cf0d0000 pid=3535 execve guuid=50eef1c2-1800-0000-d05e-f2d2d10d0000 pid=3537 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=50eef1c2-1800-0000-d05e-f2d2d10d0000 pid=3537 execve guuid=bccd5dc3-1800-0000-d05e-f2d2d40d0000 pid=3540 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=bccd5dc3-1800-0000-d05e-f2d2d40d0000 pid=3540 execve guuid=c073bfc3-1800-0000-d05e-f2d2d60d0000 pid=3542 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=c073bfc3-1800-0000-d05e-f2d2d60d0000 pid=3542 execve guuid=9d0527c4-1800-0000-d05e-f2d2d80d0000 pid=3544 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=9d0527c4-1800-0000-d05e-f2d2d80d0000 pid=3544 execve guuid=a18794c4-1800-0000-d05e-f2d2da0d0000 pid=3546 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=a18794c4-1800-0000-d05e-f2d2da0d0000 pid=3546 execve guuid=705700c5-1800-0000-d05e-f2d2dd0d0000 pid=3549 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=705700c5-1800-0000-d05e-f2d2dd0d0000 pid=3549 execve guuid=2af272c5-1800-0000-d05e-f2d2df0d0000 pid=3551 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=2af272c5-1800-0000-d05e-f2d2df0d0000 pid=3551 execve guuid=207ae1c5-1800-0000-d05e-f2d2e10d0000 pid=3553 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=207ae1c5-1800-0000-d05e-f2d2e10d0000 pid=3553 execve guuid=72514cc6-1800-0000-d05e-f2d2e30d0000 pid=3555 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=72514cc6-1800-0000-d05e-f2d2e30d0000 pid=3555 execve guuid=3ed8bfc6-1800-0000-d05e-f2d2e60d0000 pid=3558 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=3ed8bfc6-1800-0000-d05e-f2d2e60d0000 pid=3558 execve guuid=56772fc7-1800-0000-d05e-f2d2e80d0000 pid=3560 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=56772fc7-1800-0000-d05e-f2d2e80d0000 pid=3560 execve guuid=f7ff9dc7-1800-0000-d05e-f2d2ea0d0000 pid=3562 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=f7ff9dc7-1800-0000-d05e-f2d2ea0d0000 pid=3562 execve guuid=412911c8-1800-0000-d05e-f2d2ec0d0000 pid=3564 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=412911c8-1800-0000-d05e-f2d2ec0d0000 pid=3564 execve guuid=a61380c8-1800-0000-d05e-f2d2ef0d0000 pid=3567 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=a61380c8-1800-0000-d05e-f2d2ef0d0000 pid=3567 execve guuid=e7a717c9-1800-0000-d05e-f2d2f10d0000 pid=3569 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e7a717c9-1800-0000-d05e-f2d2f10d0000 pid=3569 execve guuid=ef3887c9-1800-0000-d05e-f2d2f30d0000 pid=3571 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ef3887c9-1800-0000-d05e-f2d2f30d0000 pid=3571 execve guuid=341b1bca-1800-0000-d05e-f2d2f60d0000 pid=3574 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=341b1bca-1800-0000-d05e-f2d2f60d0000 pid=3574 execve guuid=aa70b8ca-1800-0000-d05e-f2d2f80d0000 pid=3576 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=aa70b8ca-1800-0000-d05e-f2d2f80d0000 pid=3576 execve guuid=c4a112cb-1800-0000-d05e-f2d2fb0d0000 pid=3579 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=c4a112cb-1800-0000-d05e-f2d2fb0d0000 pid=3579 execve guuid=d74835cc-1800-0000-d05e-f2d2ff0d0000 pid=3583 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=d74835cc-1800-0000-d05e-f2d2ff0d0000 pid=3583 execve guuid=a858a5cc-1800-0000-d05e-f2d2020e0000 pid=3586 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=a858a5cc-1800-0000-d05e-f2d2020e0000 pid=3586 execve guuid=1d4b4fcd-1800-0000-d05e-f2d2050e0000 pid=3589 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=1d4b4fcd-1800-0000-d05e-f2d2050e0000 pid=3589 execve guuid=13beedcd-1800-0000-d05e-f2d2090e0000 pid=3593 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=13beedcd-1800-0000-d05e-f2d2090e0000 pid=3593 execve guuid=306659ce-1800-0000-d05e-f2d20b0e0000 pid=3595 /usr/bin/ls guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=306659ce-1800-0000-d05e-f2d20b0e0000 pid=3595 execve guuid=60d8b3ce-1800-0000-d05e-f2d20d0e0000 pid=3597 /usr/bin/rm guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=60d8b3ce-1800-0000-d05e-f2d20d0e0000 pid=3597 execve guuid=e1e8f3ce-1800-0000-d05e-f2d20e0e0000 pid=3598 /usr/bin/wget net send-data write-file guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e1e8f3ce-1800-0000-d05e-f2d20e0e0000 pid=3598 execve guuid=f39700d8-1800-0000-d05e-f2d21a0e0000 pid=3610 /usr/bin/chmod guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=f39700d8-1800-0000-d05e-f2d21a0e0000 pid=3610 execve guuid=cad772d8-1800-0000-d05e-f2d21c0e0000 pid=3612 /tmp/47H guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=cad772d8-1800-0000-d05e-f2d21c0e0000 pid=3612 execve guuid=40b8b2d9-1800-0000-d05e-f2d2200e0000 pid=3616 /usr/bin/rm guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=40b8b2d9-1800-0000-d05e-f2d2200e0000 pid=3616 execve guuid=b503efd9-1800-0000-d05e-f2d2210e0000 pid=3617 /usr/bin/wget net send-data write-file guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=b503efd9-1800-0000-d05e-f2d2210e0000 pid=3617 execve guuid=6d5846e1-1800-0000-d05e-f2d22c0e0000 pid=3628 /usr/bin/chmod guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=6d5846e1-1800-0000-d05e-f2d22c0e0000 pid=3628 execve guuid=3955cce1-1800-0000-d05e-f2d22d0e0000 pid=3629 /tmp/m1Aj guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=3955cce1-1800-0000-d05e-f2d22d0e0000 pid=3629 execve guuid=faf2a4e3-1800-0000-d05e-f2d2300e0000 pid=3632 /usr/bin/rm guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=faf2a4e3-1800-0000-d05e-f2d2300e0000 pid=3632 execve guuid=bb3405e4-1800-0000-d05e-f2d2310e0000 pid=3633 /usr/bin/wget net send-data write-file guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=bb3405e4-1800-0000-d05e-f2d2310e0000 pid=3633 execve guuid=8402c9ea-1800-0000-d05e-f2d23f0e0000 pid=3647 /usr/bin/chmod guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=8402c9ea-1800-0000-d05e-f2d23f0e0000 pid=3647 execve guuid=e4bf03eb-1800-0000-d05e-f2d2410e0000 pid=3649 /tmp/clZO guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e4bf03eb-1800-0000-d05e-f2d2410e0000 pid=3649 execve guuid=c363a9eb-1800-0000-d05e-f2d2440e0000 pid=3652 /usr/bin/rm guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=c363a9eb-1800-0000-d05e-f2d2440e0000 pid=3652 execve guuid=ff630aec-1800-0000-d05e-f2d2460e0000 pid=3654 /usr/bin/wget net send-data write-file guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=ff630aec-1800-0000-d05e-f2d2460e0000 pid=3654 execve guuid=afd1582f-1900-0000-d05e-f2d2d90e0000 pid=3801 /usr/bin/chmod guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=afd1582f-1900-0000-d05e-f2d2d90e0000 pid=3801 execve guuid=6f2e9b2f-1900-0000-d05e-f2d2da0e0000 pid=3802 /tmp/RZv guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=6f2e9b2f-1900-0000-d05e-f2d2da0e0000 pid=3802 execve guuid=bb103131-1900-0000-d05e-f2d2dc0e0000 pid=3804 /usr/bin/rm guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=bb103131-1900-0000-d05e-f2d2dc0e0000 pid=3804 execve guuid=81719531-1900-0000-d05e-f2d2dd0e0000 pid=3805 /usr/bin/wget net send-data write-file guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=81719531-1900-0000-d05e-f2d2dd0e0000 pid=3805 execve guuid=e38d9f39-1900-0000-d05e-f2d2f20e0000 pid=3826 /usr/bin/chmod guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=e38d9f39-1900-0000-d05e-f2d2f20e0000 pid=3826 execve guuid=2e09fe39-1900-0000-d05e-f2d2f60e0000 pid=3830 /tmp/sP9 guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=2e09fe39-1900-0000-d05e-f2d2f60e0000 pid=3830 execve guuid=2e87163d-1900-0000-d05e-f2d2fc0e0000 pid=3836 /usr/bin/rm delete-file guuid=80c0fd99-1800-0000-d05e-f2d2050d0000 pid=3333->guuid=2e87163d-1900-0000-d05e-f2d2fc0e0000 pid=3836 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=e1e8f3ce-1800-0000-d05e-f2d20e0e0000 pid=3598->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=b503efd9-1800-0000-d05e-f2d2210e0000 pid=3617->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=bb3405e4-1800-0000-d05e-f2d2310e0000 pid=3633->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=ff630aec-1800-0000-d05e-f2d2460e0000 pid=3654->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=81719531-1900-0000-d05e-f2d2dd0e0000 pid=3805->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-03 01:36:33 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7681e29bcb8b6f448cf99cff2c25ae3fa76cde3e67bd36681280ea333fa20636

(this sample)

  
Delivery method
Distributed via web download

Comments