MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e2eca854b9b34b092df5c394caa19c8b4e9302167ae44edf50407c5fe59ecad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 7e2eca854b9b34b092df5c394caa19c8b4e9302167ae44edf50407c5fe59ecad
SHA3-384 hash: 46cf1d75f0a9fa0e48b6a385c438b6d19b69eaead5b23b03b37b81eb6e9961e48285f362545b83fd35a57539e92ddf3b
SHA1 hash: 495cf2ae131bfeb233181e26765b5343b40ce611
MD5 hash: fd40d934e903a5698722e8d4ad3cd25a
humanhash: football-carbon-connecticut-stream
File name:lil
Download: download sample
File size:839 bytes
First seen:2026-06-08 07:52:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaaxUuQi/2vsFF90X:e9Qp+MsaPQ42k/90X
TLSH T15D01AFCEC026D75011D9E49D22D75045B812C3CB25468FB6BEAC547DCBBDE08B015F84
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/vvArn/an/aelf ua-wget
http://188.132.232.81/XzWBn/an/aelf ua-wget
http://188.132.232.81/Guon/an/aelf ua-wget
http://188.132.232.81/cjzn/an/aelf ua-wget
http://188.132.232.81/HfQn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-08T04:57:00Z UTC
Last seen:
2026-06-08T04:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f9ec8d9e-2f00-0000-f8b9-aeabb3030000 pid=947 /usr/bin/sudo guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948 /tmp/sample.bin write-file guuid=f9ec8d9e-2f00-0000-f8b9-aeabb3030000 pid=947->guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948 execve guuid=6bd626a2-2f00-0000-f8b9-aeabb5030000 pid=949 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=6bd626a2-2f00-0000-f8b9-aeabb5030000 pid=949 execve guuid=f340a1a2-2f00-0000-f8b9-aeabb6030000 pid=950 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f340a1a2-2f00-0000-f8b9-aeabb6030000 pid=950 execve guuid=30f713a3-2f00-0000-f8b9-aeabb7030000 pid=951 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=30f713a3-2f00-0000-f8b9-aeabb7030000 pid=951 execve guuid=94ce09a4-2f00-0000-f8b9-aeabb8030000 pid=952 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=94ce09a4-2f00-0000-f8b9-aeabb8030000 pid=952 execve guuid=c8e69aa4-2f00-0000-f8b9-aeabb9030000 pid=953 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=c8e69aa4-2f00-0000-f8b9-aeabb9030000 pid=953 execve guuid=3c2b18a5-2f00-0000-f8b9-aeabba030000 pid=954 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3c2b18a5-2f00-0000-f8b9-aeabba030000 pid=954 execve guuid=6d1598a5-2f00-0000-f8b9-aeabbb030000 pid=955 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=6d1598a5-2f00-0000-f8b9-aeabbb030000 pid=955 execve guuid=1fe912a6-2f00-0000-f8b9-aeabbc030000 pid=956 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=1fe912a6-2f00-0000-f8b9-aeabbc030000 pid=956 execve guuid=3660f5a6-2f00-0000-f8b9-aeabbd030000 pid=957 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3660f5a6-2f00-0000-f8b9-aeabbd030000 pid=957 execve guuid=e97375a7-2f00-0000-f8b9-aeabbe030000 pid=958 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=e97375a7-2f00-0000-f8b9-aeabbe030000 pid=958 execve guuid=59cbe0a7-2f00-0000-f8b9-aeabbf030000 pid=959 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=59cbe0a7-2f00-0000-f8b9-aeabbf030000 pid=959 execve guuid=5efc83a8-2f00-0000-f8b9-aeabc0030000 pid=960 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=5efc83a8-2f00-0000-f8b9-aeabc0030000 pid=960 execve guuid=e82e4ea9-2f00-0000-f8b9-aeabc1030000 pid=961 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=e82e4ea9-2f00-0000-f8b9-aeabc1030000 pid=961 execve guuid=3de6c8a9-2f00-0000-f8b9-aeabc2030000 pid=962 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3de6c8a9-2f00-0000-f8b9-aeabc2030000 pid=962 execve guuid=d82577aa-2f00-0000-f8b9-aeabc3030000 pid=963 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=d82577aa-2f00-0000-f8b9-aeabc3030000 pid=963 execve guuid=fbfcf3aa-2f00-0000-f8b9-aeabc4030000 pid=964 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=fbfcf3aa-2f00-0000-f8b9-aeabc4030000 pid=964 execve guuid=19ae65ab-2f00-0000-f8b9-aeabc5030000 pid=965 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=19ae65ab-2f00-0000-f8b9-aeabc5030000 pid=965 execve guuid=1933d9ab-2f00-0000-f8b9-aeabc6030000 pid=966 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=1933d9ab-2f00-0000-f8b9-aeabc6030000 pid=966 execve guuid=f8fe57ac-2f00-0000-f8b9-aeabc7030000 pid=967 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f8fe57ac-2f00-0000-f8b9-aeabc7030000 pid=967 execve guuid=3274d4ac-2f00-0000-f8b9-aeabc8030000 pid=968 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3274d4ac-2f00-0000-f8b9-aeabc8030000 pid=968 execve guuid=bb014fad-2f00-0000-f8b9-aeabc9030000 pid=969 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=bb014fad-2f00-0000-f8b9-aeabc9030000 pid=969 execve guuid=7ec2c2ad-2f00-0000-f8b9-aeabca030000 pid=970 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=7ec2c2ad-2f00-0000-f8b9-aeabca030000 pid=970 execve guuid=9a9048ae-2f00-0000-f8b9-aeabcb030000 pid=971 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=9a9048ae-2f00-0000-f8b9-aeabcb030000 pid=971 execve guuid=75ffbfae-2f00-0000-f8b9-aeabcc030000 pid=972 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=75ffbfae-2f00-0000-f8b9-aeabcc030000 pid=972 execve guuid=9c8c37af-2f00-0000-f8b9-aeabcd030000 pid=973 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=9c8c37af-2f00-0000-f8b9-aeabcd030000 pid=973 execve guuid=0580a9af-2f00-0000-f8b9-aeabce030000 pid=974 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=0580a9af-2f00-0000-f8b9-aeabce030000 pid=974 execve guuid=6b612fb0-2f00-0000-f8b9-aeabcf030000 pid=975 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=6b612fb0-2f00-0000-f8b9-aeabcf030000 pid=975 execve guuid=14aea4b0-2f00-0000-f8b9-aeabd0030000 pid=976 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=14aea4b0-2f00-0000-f8b9-aeabd0030000 pid=976 execve guuid=82b426b1-2f00-0000-f8b9-aeabd1030000 pid=977 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=82b426b1-2f00-0000-f8b9-aeabd1030000 pid=977 execve guuid=34b89ab1-2f00-0000-f8b9-aeabd2030000 pid=978 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=34b89ab1-2f00-0000-f8b9-aeabd2030000 pid=978 execve guuid=848c06b2-2f00-0000-f8b9-aeabd3030000 pid=979 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=848c06b2-2f00-0000-f8b9-aeabd3030000 pid=979 execve guuid=e38a73b2-2f00-0000-f8b9-aeabd4030000 pid=980 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=e38a73b2-2f00-0000-f8b9-aeabd4030000 pid=980 execve guuid=9708cdb2-2f00-0000-f8b9-aeabd5030000 pid=981 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=9708cdb2-2f00-0000-f8b9-aeabd5030000 pid=981 execve guuid=32473ab3-2f00-0000-f8b9-aeabd6030000 pid=982 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=32473ab3-2f00-0000-f8b9-aeabd6030000 pid=982 execve guuid=4a619cb3-2f00-0000-f8b9-aeabd7030000 pid=983 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=4a619cb3-2f00-0000-f8b9-aeabd7030000 pid=983 execve guuid=792f08b4-2f00-0000-f8b9-aeabd8030000 pid=984 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=792f08b4-2f00-0000-f8b9-aeabd8030000 pid=984 execve guuid=3cc968b4-2f00-0000-f8b9-aeabd9030000 pid=985 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3cc968b4-2f00-0000-f8b9-aeabd9030000 pid=985 execve guuid=f116d7b4-2f00-0000-f8b9-aeabda030000 pid=986 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f116d7b4-2f00-0000-f8b9-aeabda030000 pid=986 execve guuid=bff831b5-2f00-0000-f8b9-aeabdb030000 pid=987 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=bff831b5-2f00-0000-f8b9-aeabdb030000 pid=987 execve guuid=cb938ab5-2f00-0000-f8b9-aeabdc030000 pid=988 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=cb938ab5-2f00-0000-f8b9-aeabdc030000 pid=988 execve guuid=870cdeb5-2f00-0000-f8b9-aeabdd030000 pid=989 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=870cdeb5-2f00-0000-f8b9-aeabdd030000 pid=989 execve guuid=25f156b6-2f00-0000-f8b9-aeabde030000 pid=990 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=25f156b6-2f00-0000-f8b9-aeabde030000 pid=990 execve guuid=8c44d5b6-2f00-0000-f8b9-aeabdf030000 pid=991 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=8c44d5b6-2f00-0000-f8b9-aeabdf030000 pid=991 execve guuid=852036b7-2f00-0000-f8b9-aeabe0030000 pid=992 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=852036b7-2f00-0000-f8b9-aeabe0030000 pid=992 execve guuid=31fbc1b7-2f00-0000-f8b9-aeabe1030000 pid=993 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=31fbc1b7-2f00-0000-f8b9-aeabe1030000 pid=993 execve guuid=c09a3fb8-2f00-0000-f8b9-aeabe2030000 pid=994 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=c09a3fb8-2f00-0000-f8b9-aeabe2030000 pid=994 execve guuid=c226f7b8-2f00-0000-f8b9-aeabe3030000 pid=995 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=c226f7b8-2f00-0000-f8b9-aeabe3030000 pid=995 execve guuid=8a4a8db9-2f00-0000-f8b9-aeabe4030000 pid=996 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=8a4a8db9-2f00-0000-f8b9-aeabe4030000 pid=996 execve guuid=fa0745ba-2f00-0000-f8b9-aeabe5030000 pid=997 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=fa0745ba-2f00-0000-f8b9-aeabe5030000 pid=997 execve guuid=c0edc5ba-2f00-0000-f8b9-aeabe6030000 pid=998 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=c0edc5ba-2f00-0000-f8b9-aeabe6030000 pid=998 execve guuid=5d5368bb-2f00-0000-f8b9-aeabe7030000 pid=999 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=5d5368bb-2f00-0000-f8b9-aeabe7030000 pid=999 execve guuid=de26ebbb-2f00-0000-f8b9-aeabe8030000 pid=1000 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=de26ebbb-2f00-0000-f8b9-aeabe8030000 pid=1000 execve guuid=3dfa91bc-2f00-0000-f8b9-aeabe9030000 pid=1001 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3dfa91bc-2f00-0000-f8b9-aeabe9030000 pid=1001 execve guuid=a4ccf5bc-2f00-0000-f8b9-aeabea030000 pid=1002 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=a4ccf5bc-2f00-0000-f8b9-aeabea030000 pid=1002 execve guuid=b0228abd-2f00-0000-f8b9-aeabeb030000 pid=1003 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=b0228abd-2f00-0000-f8b9-aeabeb030000 pid=1003 execve guuid=4562e4bd-2f00-0000-f8b9-aeabec030000 pid=1004 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=4562e4bd-2f00-0000-f8b9-aeabec030000 pid=1004 execve guuid=ef127fbe-2f00-0000-f8b9-aeabed030000 pid=1005 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=ef127fbe-2f00-0000-f8b9-aeabed030000 pid=1005 execve guuid=3e652dbf-2f00-0000-f8b9-aeabee030000 pid=1006 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3e652dbf-2f00-0000-f8b9-aeabee030000 pid=1006 execve guuid=ef51c9bf-2f00-0000-f8b9-aeabef030000 pid=1007 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=ef51c9bf-2f00-0000-f8b9-aeabef030000 pid=1007 execve guuid=29e960c0-2f00-0000-f8b9-aeabf0030000 pid=1008 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=29e960c0-2f00-0000-f8b9-aeabf0030000 pid=1008 execve guuid=2db519c1-2f00-0000-f8b9-aeabf1030000 pid=1009 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=2db519c1-2f00-0000-f8b9-aeabf1030000 pid=1009 execve guuid=36adc0c1-2f00-0000-f8b9-aeabf2030000 pid=1010 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=36adc0c1-2f00-0000-f8b9-aeabf2030000 pid=1010 execve guuid=4f308bc2-2f00-0000-f8b9-aeabf3030000 pid=1011 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=4f308bc2-2f00-0000-f8b9-aeabf3030000 pid=1011 execve guuid=12ff1bc3-2f00-0000-f8b9-aeabf4030000 pid=1012 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=12ff1bc3-2f00-0000-f8b9-aeabf4030000 pid=1012 execve guuid=7888b4c3-2f00-0000-f8b9-aeabf5030000 pid=1013 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=7888b4c3-2f00-0000-f8b9-aeabf5030000 pid=1013 execve guuid=b1882ec4-2f00-0000-f8b9-aeabf6030000 pid=1014 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=b1882ec4-2f00-0000-f8b9-aeabf6030000 pid=1014 execve guuid=19f0d3c4-2f00-0000-f8b9-aeabf7030000 pid=1015 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=19f0d3c4-2f00-0000-f8b9-aeabf7030000 pid=1015 execve guuid=563f3cc5-2f00-0000-f8b9-aeabf8030000 pid=1016 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=563f3cc5-2f00-0000-f8b9-aeabf8030000 pid=1016 execve guuid=4e13a7c5-2f00-0000-f8b9-aeabf9030000 pid=1017 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=4e13a7c5-2f00-0000-f8b9-aeabf9030000 pid=1017 execve guuid=99e44ac6-2f00-0000-f8b9-aeabfa030000 pid=1018 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=99e44ac6-2f00-0000-f8b9-aeabfa030000 pid=1018 execve guuid=d1e5f6c6-2f00-0000-f8b9-aeabfb030000 pid=1019 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=d1e5f6c6-2f00-0000-f8b9-aeabfb030000 pid=1019 execve guuid=1fb6dbc7-2f00-0000-f8b9-aeabfc030000 pid=1020 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=1fb6dbc7-2f00-0000-f8b9-aeabfc030000 pid=1020 execve guuid=f9e6aec8-2f00-0000-f8b9-aeabfd030000 pid=1021 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f9e6aec8-2f00-0000-f8b9-aeabfd030000 pid=1021 execve guuid=f7e48fc9-2f00-0000-f8b9-aeabfe030000 pid=1022 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f7e48fc9-2f00-0000-f8b9-aeabfe030000 pid=1022 execve guuid=0e8428ca-2f00-0000-f8b9-aeabff030000 pid=1023 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=0e8428ca-2f00-0000-f8b9-aeabff030000 pid=1023 execve guuid=1c98aeca-2f00-0000-f8b9-aeab00040000 pid=1024 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=1c98aeca-2f00-0000-f8b9-aeab00040000 pid=1024 execve guuid=f03933cb-2f00-0000-f8b9-aeab01040000 pid=1025 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f03933cb-2f00-0000-f8b9-aeab01040000 pid=1025 execve guuid=2f3cb5cb-2f00-0000-f8b9-aeab02040000 pid=1026 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=2f3cb5cb-2f00-0000-f8b9-aeab02040000 pid=1026 execve guuid=4bc22ecc-2f00-0000-f8b9-aeab03040000 pid=1027 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=4bc22ecc-2f00-0000-f8b9-aeab03040000 pid=1027 execve guuid=605da2cc-2f00-0000-f8b9-aeab04040000 pid=1028 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=605da2cc-2f00-0000-f8b9-aeab04040000 pid=1028 execve guuid=b74e30cd-2f00-0000-f8b9-aeab05040000 pid=1029 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=b74e30cd-2f00-0000-f8b9-aeab05040000 pid=1029 execve guuid=6e04a9cd-2f00-0000-f8b9-aeab06040000 pid=1030 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=6e04a9cd-2f00-0000-f8b9-aeab06040000 pid=1030 execve guuid=12f343ce-2f00-0000-f8b9-aeab07040000 pid=1031 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=12f343ce-2f00-0000-f8b9-aeab07040000 pid=1031 execve guuid=f840dfce-2f00-0000-f8b9-aeab08040000 pid=1032 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f840dfce-2f00-0000-f8b9-aeab08040000 pid=1032 execve guuid=20eb94cf-2f00-0000-f8b9-aeab09040000 pid=1033 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=20eb94cf-2f00-0000-f8b9-aeab09040000 pid=1033 execve guuid=baf532d0-2f00-0000-f8b9-aeab0a040000 pid=1034 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=baf532d0-2f00-0000-f8b9-aeab0a040000 pid=1034 execve guuid=48deacd0-2f00-0000-f8b9-aeab0b040000 pid=1035 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=48deacd0-2f00-0000-f8b9-aeab0b040000 pid=1035 execve guuid=de6d19d1-2f00-0000-f8b9-aeab0c040000 pid=1036 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=de6d19d1-2f00-0000-f8b9-aeab0c040000 pid=1036 execve guuid=042b88d1-2f00-0000-f8b9-aeab0d040000 pid=1037 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=042b88d1-2f00-0000-f8b9-aeab0d040000 pid=1037 execve guuid=a28efad1-2f00-0000-f8b9-aeab0e040000 pid=1038 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=a28efad1-2f00-0000-f8b9-aeab0e040000 pid=1038 execve guuid=270063d2-2f00-0000-f8b9-aeab0f040000 pid=1039 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=270063d2-2f00-0000-f8b9-aeab0f040000 pid=1039 execve guuid=7dd2b6d2-2f00-0000-f8b9-aeab10040000 pid=1040 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=7dd2b6d2-2f00-0000-f8b9-aeab10040000 pid=1040 execve guuid=ae5b1ed3-2f00-0000-f8b9-aeab11040000 pid=1041 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=ae5b1ed3-2f00-0000-f8b9-aeab11040000 pid=1041 execve guuid=dd7882d3-2f00-0000-f8b9-aeab12040000 pid=1042 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=dd7882d3-2f00-0000-f8b9-aeab12040000 pid=1042 execve guuid=e42eebd3-2f00-0000-f8b9-aeab13040000 pid=1043 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=e42eebd3-2f00-0000-f8b9-aeab13040000 pid=1043 execve guuid=d3f94dd4-2f00-0000-f8b9-aeab14040000 pid=1044 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=d3f94dd4-2f00-0000-f8b9-aeab14040000 pid=1044 execve guuid=67ffbcd4-2f00-0000-f8b9-aeab15040000 pid=1045 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=67ffbcd4-2f00-0000-f8b9-aeab15040000 pid=1045 execve guuid=807e18d5-2f00-0000-f8b9-aeab16040000 pid=1046 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=807e18d5-2f00-0000-f8b9-aeab16040000 pid=1046 execve guuid=00117ad5-2f00-0000-f8b9-aeab17040000 pid=1047 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=00117ad5-2f00-0000-f8b9-aeab17040000 pid=1047 execve guuid=dbd9d4d5-2f00-0000-f8b9-aeab18040000 pid=1048 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=dbd9d4d5-2f00-0000-f8b9-aeab18040000 pid=1048 execve guuid=33da31d6-2f00-0000-f8b9-aeab19040000 pid=1049 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=33da31d6-2f00-0000-f8b9-aeab19040000 pid=1049 execve guuid=14fc90d6-2f00-0000-f8b9-aeab1a040000 pid=1050 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=14fc90d6-2f00-0000-f8b9-aeab1a040000 pid=1050 execve guuid=9a7cf1d6-2f00-0000-f8b9-aeab1b040000 pid=1051 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=9a7cf1d6-2f00-0000-f8b9-aeab1b040000 pid=1051 execve guuid=c87d4bd7-2f00-0000-f8b9-aeab1c040000 pid=1052 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=c87d4bd7-2f00-0000-f8b9-aeab1c040000 pid=1052 execve guuid=8001aad7-2f00-0000-f8b9-aeab1d040000 pid=1053 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=8001aad7-2f00-0000-f8b9-aeab1d040000 pid=1053 execve guuid=3f8305d8-2f00-0000-f8b9-aeab1e040000 pid=1054 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3f8305d8-2f00-0000-f8b9-aeab1e040000 pid=1054 execve guuid=7d927dd8-2f00-0000-f8b9-aeab1f040000 pid=1055 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=7d927dd8-2f00-0000-f8b9-aeab1f040000 pid=1055 execve guuid=3a761bd9-2f00-0000-f8b9-aeab20040000 pid=1056 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=3a761bd9-2f00-0000-f8b9-aeab20040000 pid=1056 execve guuid=232aa4d9-2f00-0000-f8b9-aeab21040000 pid=1057 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=232aa4d9-2f00-0000-f8b9-aeab21040000 pid=1057 execve guuid=13ea1dda-2f00-0000-f8b9-aeab22040000 pid=1058 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=13ea1dda-2f00-0000-f8b9-aeab22040000 pid=1058 execve guuid=51328ada-2f00-0000-f8b9-aeab23040000 pid=1059 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=51328ada-2f00-0000-f8b9-aeab23040000 pid=1059 execve guuid=1528efda-2f00-0000-f8b9-aeab24040000 pid=1060 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=1528efda-2f00-0000-f8b9-aeab24040000 pid=1060 execve guuid=16c342db-2f00-0000-f8b9-aeab25040000 pid=1061 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=16c342db-2f00-0000-f8b9-aeab25040000 pid=1061 execve guuid=d0709cdb-2f00-0000-f8b9-aeab26040000 pid=1062 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=d0709cdb-2f00-0000-f8b9-aeab26040000 pid=1062 execve guuid=bf06fadb-2f00-0000-f8b9-aeab27040000 pid=1063 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=bf06fadb-2f00-0000-f8b9-aeab27040000 pid=1063 execve guuid=32bc58dc-2f00-0000-f8b9-aeab28040000 pid=1064 /usr/bin/ls guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=32bc58dc-2f00-0000-f8b9-aeab28040000 pid=1064 execve guuid=5b60b5dc-2f00-0000-f8b9-aeab29040000 pid=1065 /usr/bin/rm guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=5b60b5dc-2f00-0000-f8b9-aeab29040000 pid=1065 execve guuid=2f07f7dc-2f00-0000-f8b9-aeab2a040000 pid=1066 /usr/bin/wget net send-data write-file guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=2f07f7dc-2f00-0000-f8b9-aeab2a040000 pid=1066 execve guuid=0f0a0b52-3100-0000-f8b9-aeab2b040000 pid=1067 /usr/bin/chmod guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=0f0a0b52-3100-0000-f8b9-aeab2b040000 pid=1067 execve guuid=f39f9652-3100-0000-f8b9-aeab2c040000 pid=1068 /tmp/vvAr guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=f39f9652-3100-0000-f8b9-aeab2c040000 pid=1068 execve guuid=46397896-3100-0000-f8b9-aeab2e040000 pid=1070 /usr/bin/rm guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=46397896-3100-0000-f8b9-aeab2e040000 pid=1070 execve guuid=5297de96-3100-0000-f8b9-aeab2f040000 pid=1071 /usr/bin/wget net send-data write-file guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=5297de96-3100-0000-f8b9-aeab2f040000 pid=1071 execve guuid=0054cabb-3100-0000-f8b9-aeab30040000 pid=1072 /usr/bin/chmod guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=0054cabb-3100-0000-f8b9-aeab30040000 pid=1072 execve guuid=6c6550bc-3100-0000-f8b9-aeab31040000 pid=1073 /tmp/XzWB guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=6c6550bc-3100-0000-f8b9-aeab31040000 pid=1073 execve guuid=6395fcbd-3100-0000-f8b9-aeab33040000 pid=1075 /usr/bin/rm guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=6395fcbd-3100-0000-f8b9-aeab33040000 pid=1075 execve guuid=7d8e80be-3100-0000-f8b9-aeab34040000 pid=1076 /usr/bin/wget net send-data write-file guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=7d8e80be-3100-0000-f8b9-aeab34040000 pid=1076 execve guuid=d7181353-3200-0000-f8b9-aeab35040000 pid=1077 /usr/bin/chmod guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=d7181353-3200-0000-f8b9-aeab35040000 pid=1077 execve guuid=76359853-3200-0000-f8b9-aeab36040000 pid=1078 /tmp/Guo guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=76359853-3200-0000-f8b9-aeab36040000 pid=1078 execve guuid=d5075354-3200-0000-f8b9-aeab38040000 pid=1080 /usr/bin/rm guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=d5075354-3200-0000-f8b9-aeab38040000 pid=1080 execve guuid=c8839854-3200-0000-f8b9-aeab39040000 pid=1081 /usr/bin/wget net send-data write-file guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=c8839854-3200-0000-f8b9-aeab39040000 pid=1081 execve guuid=19364174-3200-0000-f8b9-aeab3a040000 pid=1082 /usr/bin/chmod guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=19364174-3200-0000-f8b9-aeab3a040000 pid=1082 execve guuid=80bbf174-3200-0000-f8b9-aeab3b040000 pid=1083 /tmp/cjz guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=80bbf174-3200-0000-f8b9-aeab3b040000 pid=1083 execve guuid=2e6ce775-3200-0000-f8b9-aeab3d040000 pid=1085 /usr/bin/rm guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=2e6ce775-3200-0000-f8b9-aeab3d040000 pid=1085 execve guuid=50103376-3200-0000-f8b9-aeab3e040000 pid=1086 /usr/bin/wget net send-data write-file guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=50103376-3200-0000-f8b9-aeab3e040000 pid=1086 execve guuid=8dca627e-3200-0000-f8b9-aeab3f040000 pid=1087 /usr/bin/chmod guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=8dca627e-3200-0000-f8b9-aeab3f040000 pid=1087 execve guuid=5998b27e-3200-0000-f8b9-aeab40040000 pid=1088 /tmp/HfQ guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=5998b27e-3200-0000-f8b9-aeab40040000 pid=1088 execve guuid=9d18a77f-3200-0000-f8b9-aeab42040000 pid=1090 /usr/bin/rm delete-file guuid=5f3cb7a1-2f00-0000-f8b9-aeabb4030000 pid=948->guuid=9d18a77f-3200-0000-f8b9-aeab42040000 pid=1090 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=2f07f7dc-2f00-0000-f8b9-aeab2a040000 pid=1066->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=5297de96-3100-0000-f8b9-aeab2f040000 pid=1071->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=7d8e80be-3100-0000-f8b9-aeab34040000 pid=1076->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=c8839854-3200-0000-f8b9-aeab39040000 pid=1081->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=50103376-3200-0000-f8b9-aeab3e040000 pid=1086->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-08 07:53:26 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7e2eca854b9b34b092df5c394caa19c8b4e9302167ae44edf50407c5fe59ecad

(this sample)

  
Delivery method
Distributed via web download

Comments