MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7c04b423f7277ee260c545f9c9f9ccd1ac46ccc19d622a9d4d7dbd27dfbbca7e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 7c04b423f7277ee260c545f9c9f9ccd1ac46ccc19d622a9d4d7dbd27dfbbca7e
SHA3-384 hash: 40305d806b8901964d65642cf2f75a99e401a50f29537e2da7e4c6154f5a95afbb5d5b6e98785d58c0e2dc775037ace3
SHA1 hash: 6824b0e0fb83febf27661d4daa51fd73a2cfbeb3
MD5 hash: 8d91bb84d08160e03369093aca9f3b62
humanhash: oklahoma-don-pip-lion
File name:wr.php
Download: download sample
File size:27'042 bytes
First seen:2026-07-24 00:08:14 UTC
Last seen:2026-07-24 07:46:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 768:L8vCB+25j6es8RE9FYpMSUpi+20qUpi+20YQX:L8l25Jid2QX
TLSH T122C28D956A867C44BEC94A3E4CBD2B0D6DF5C3D1324952AC3D8B3C719C11FACC618B1A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.119.69.4/z/post/noroot.phpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=197c7dee-1d00-0000-e07e-64b1ce130000 pid=5070 /usr/bin/sudo guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071 /tmp/sample.bin guuid=197c7dee-1d00-0000-e07e-64b1ce130000 pid=5070->guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071 execve guuid=210f97f1-1d00-0000-e07e-64b1d0130000 pid=5072 /usr/bin/bash guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=210f97f1-1d00-0000-e07e-64b1d0130000 pid=5072 clone guuid=a9fe9df1-1d00-0000-e07e-64b1d1130000 pid=5073 /usr/bin/base64 guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=a9fe9df1-1d00-0000-e07e-64b1d1130000 pid=5073 execve guuid=0c82a7f1-1d00-0000-e07e-64b1d2130000 pid=5074 /usr/bin/bash guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=0c82a7f1-1d00-0000-e07e-64b1d2130000 pid=5074 clone guuid=cfd7eef3-1d00-0000-e07e-64b1d3130000 pid=5075 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=cfd7eef3-1d00-0000-e07e-64b1d3130000 pid=5075 execve guuid=956a86f4-1d00-0000-e07e-64b1d4130000 pid=5076 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=956a86f4-1d00-0000-e07e-64b1d4130000 pid=5076 execve guuid=165afef4-1d00-0000-e07e-64b1d5130000 pid=5077 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=165afef4-1d00-0000-e07e-64b1d5130000 pid=5077 execve guuid=e1645ff5-1d00-0000-e07e-64b1d6130000 pid=5078 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=e1645ff5-1d00-0000-e07e-64b1d6130000 pid=5078 execve guuid=b0fcbef5-1d00-0000-e07e-64b1d7130000 pid=5079 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=b0fcbef5-1d00-0000-e07e-64b1d7130000 pid=5079 execve guuid=f43818f6-1d00-0000-e07e-64b1d8130000 pid=5080 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=f43818f6-1d00-0000-e07e-64b1d8130000 pid=5080 execve guuid=743f6ef6-1d00-0000-e07e-64b1da130000 pid=5082 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=743f6ef6-1d00-0000-e07e-64b1da130000 pid=5082 execve guuid=fcc8cdf6-1d00-0000-e07e-64b1db130000 pid=5083 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=fcc8cdf6-1d00-0000-e07e-64b1db130000 pid=5083 execve guuid=c23643f7-1d00-0000-e07e-64b1dc130000 pid=5084 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=c23643f7-1d00-0000-e07e-64b1dc130000 pid=5084 execve guuid=4d2896f7-1d00-0000-e07e-64b1dd130000 pid=5085 /usr/bin/mkdir guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=4d2896f7-1d00-0000-e07e-64b1dd130000 pid=5085 execve guuid=a023edf7-1d00-0000-e07e-64b1de130000 pid=5086 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=a023edf7-1d00-0000-e07e-64b1de130000 pid=5086 execve guuid=2f45a4f8-1d00-0000-e07e-64b1df130000 pid=5087 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=2f45a4f8-1d00-0000-e07e-64b1df130000 pid=5087 execve guuid=18787ff9-1d00-0000-e07e-64b1e0130000 pid=5088 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=18787ff9-1d00-0000-e07e-64b1e0130000 pid=5088 execve guuid=8c6d2dfa-1d00-0000-e07e-64b1e1130000 pid=5089 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=8c6d2dfa-1d00-0000-e07e-64b1e1130000 pid=5089 execve guuid=0785dcfa-1d00-0000-e07e-64b1e2130000 pid=5090 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=0785dcfa-1d00-0000-e07e-64b1e2130000 pid=5090 execve guuid=db298dfb-1d00-0000-e07e-64b1e3130000 pid=5091 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=db298dfb-1d00-0000-e07e-64b1e3130000 pid=5091 execve guuid=ac0d1bfc-1d00-0000-e07e-64b1e4130000 pid=5092 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=ac0d1bfc-1d00-0000-e07e-64b1e4130000 pid=5092 execve guuid=0241bffc-1d00-0000-e07e-64b1e5130000 pid=5093 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=0241bffc-1d00-0000-e07e-64b1e5130000 pid=5093 execve guuid=f8a95afd-1d00-0000-e07e-64b1e6130000 pid=5094 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=f8a95afd-1d00-0000-e07e-64b1e6130000 pid=5094 execve guuid=3291fdfd-1d00-0000-e07e-64b1e8130000 pid=5096 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=3291fdfd-1d00-0000-e07e-64b1e8130000 pid=5096 execve guuid=7338e3fe-1d00-0000-e07e-64b1e9130000 pid=5097 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=7338e3fe-1d00-0000-e07e-64b1e9130000 pid=5097 execve guuid=fd03a5ff-1d00-0000-e07e-64b1ea130000 pid=5098 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=fd03a5ff-1d00-0000-e07e-64b1ea130000 pid=5098 execve guuid=7f007a00-1e00-0000-e07e-64b1eb130000 pid=5099 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=7f007a00-1e00-0000-e07e-64b1eb130000 pid=5099 execve guuid=1c484d01-1e00-0000-e07e-64b1ec130000 pid=5100 /usr/bin/cp guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=1c484d01-1e00-0000-e07e-64b1ec130000 pid=5100 execve guuid=a9153802-1e00-0000-e07e-64b1ed130000 pid=5101 /usr/bin/touch guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=a9153802-1e00-0000-e07e-64b1ed130000 pid=5101 execve guuid=be86c502-1e00-0000-e07e-64b1ee130000 pid=5102 /usr/bin/chmod guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=be86c502-1e00-0000-e07e-64b1ee130000 pid=5102 execve guuid=a7ba4503-1e00-0000-e07e-64b1ef130000 pid=5103 /usr/bin/chmod guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=a7ba4503-1e00-0000-e07e-64b1ef130000 pid=5103 execve guuid=9c39d803-1e00-0000-e07e-64b1f0130000 pid=5104 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=9c39d803-1e00-0000-e07e-64b1f0130000 pid=5104 execve guuid=12077e04-1e00-0000-e07e-64b1f1130000 pid=5105 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=12077e04-1e00-0000-e07e-64b1f1130000 pid=5105 execve guuid=6e41ff04-1e00-0000-e07e-64b1f2130000 pid=5106 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=6e41ff04-1e00-0000-e07e-64b1f2130000 pid=5106 execve guuid=2cc36a05-1e00-0000-e07e-64b1f3130000 pid=5107 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=2cc36a05-1e00-0000-e07e-64b1f3130000 pid=5107 execve guuid=dee6d705-1e00-0000-e07e-64b1f4130000 pid=5108 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=dee6d705-1e00-0000-e07e-64b1f4130000 pid=5108 execve guuid=18283306-1e00-0000-e07e-64b1f5130000 pid=5109 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=18283306-1e00-0000-e07e-64b1f5130000 pid=5109 execve guuid=1b138606-1e00-0000-e07e-64b1f6130000 pid=5110 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=1b138606-1e00-0000-e07e-64b1f6130000 pid=5110 execve guuid=d79ad406-1e00-0000-e07e-64b1f7130000 pid=5111 /usr/bin/chattr guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=d79ad406-1e00-0000-e07e-64b1f7130000 pid=5111 execve guuid=4d943307-1e00-0000-e07e-64b1f9130000 pid=5113 /usr/bin/bash guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=4d943307-1e00-0000-e07e-64b1f9130000 pid=5113 clone guuid=1caf3f07-1e00-0000-e07e-64b1fa130000 pid=5114 /usr/bin/bash guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=1caf3f07-1e00-0000-e07e-64b1fa130000 pid=5114 clone guuid=e44caa07-1e00-0000-e07e-64b1fb130000 pid=5115 /usr/bin/curl net guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=e44caa07-1e00-0000-e07e-64b1fb130000 pid=5115 execve guuid=75c4c407-1e00-0000-e07e-64b1fc130000 pid=5116 /usr/bin/dash guuid=1a530df1-1d00-0000-e07e-64b1cf130000 pid=5071->guuid=75c4c407-1e00-0000-e07e-64b1fc130000 pid=5116 execve 124ee36c-bdbd-5d46-bbb1-b2cd81367f04 160.119.69.4:80 guuid=e44caa07-1e00-0000-e07e-64b1fb130000 pid=5115->124ee36c-bdbd-5d46-bbb1-b2cd81367f04 con
Threat name:
Linux.Backdoor.WebShell
Status:
Malicious
First seen:
2026-07-24 00:09:42 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7c04b423f7277ee260c545f9c9f9ccd1ac46ccc19d622a9d4d7dbd27dfbbca7e

(this sample)

  
Delivery method
Distributed via web download

Comments