MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80e48530ea78b466d1e904ecd1ff403419aee4bc789af5eaa9ddef3476e05ec6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 80e48530ea78b466d1e904ecd1ff403419aee4bc789af5eaa9ddef3476e05ec6
SHA3-384 hash: b205768efd31d67d1455fd8d3cf8b7ed7e0e6fc8d8fe3451790ff4f4731da00e971de0402603fd830c6fbf549cad1a29
SHA1 hash: de6240c42381642f3470570f34024cf588e5f17e
MD5 hash: 14aa825aeebc4e24c342e979b9d2dc85
humanhash: monkey-mike-batman-october
File name:lil
Download: download sample
File size:843 bytes
First seen:2026-06-08 05:21:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkac1IiGAf1cEI3T9IN/FnjIsejxI7tXSX:kXCKysE2hi0ziQvZohasvl6+/x4lTX
TLSH T104018CDD800A9B5011D6E89D32DB2444B828C3CB25428BB9BF6D243D8BA9A0C701AF84
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/JO6n/an/aelf ua-wget
http://188.132.232.81/Z9dIn/an/aelf ua-wget
http://188.132.232.81/c3Pn/an/aelf ua-wget
http://188.132.232.81/mnzAn/an/aelf ua-wget
http://188.132.232.81/2ke2n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-08T02:25:00Z UTC
Last seen:
2026-06-08T06:52:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=bc966229-1700-0000-f04f-ac0ef60d0000 pid=3574 /usr/bin/sudo guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582 /tmp/sample.bin write-file guuid=bc966229-1700-0000-f04f-ac0ef60d0000 pid=3574->guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582 execve guuid=0b93782b-1700-0000-f04f-ac0e000e0000 pid=3584 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0b93782b-1700-0000-f04f-ac0e000e0000 pid=3584 execve guuid=ee76e82b-1700-0000-f04f-ac0e010e0000 pid=3585 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ee76e82b-1700-0000-f04f-ac0e010e0000 pid=3585 execve guuid=045d4b2c-1700-0000-f04f-ac0e040e0000 pid=3588 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=045d4b2c-1700-0000-f04f-ac0e040e0000 pid=3588 execve guuid=2222a72c-1700-0000-f04f-ac0e060e0000 pid=3590 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=2222a72c-1700-0000-f04f-ac0e060e0000 pid=3590 execve guuid=0669fd2c-1700-0000-f04f-ac0e080e0000 pid=3592 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0669fd2c-1700-0000-f04f-ac0e080e0000 pid=3592 execve guuid=0cb6622d-1700-0000-f04f-ac0e0a0e0000 pid=3594 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0cb6622d-1700-0000-f04f-ac0e0a0e0000 pid=3594 execve guuid=352bc92d-1700-0000-f04f-ac0e0c0e0000 pid=3596 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=352bc92d-1700-0000-f04f-ac0e0c0e0000 pid=3596 execve guuid=214c282e-1700-0000-f04f-ac0e0e0e0000 pid=3598 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=214c282e-1700-0000-f04f-ac0e0e0e0000 pid=3598 execve guuid=2f3e9b2e-1700-0000-f04f-ac0e100e0000 pid=3600 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=2f3e9b2e-1700-0000-f04f-ac0e100e0000 pid=3600 execve guuid=a627032f-1700-0000-f04f-ac0e130e0000 pid=3603 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a627032f-1700-0000-f04f-ac0e130e0000 pid=3603 execve guuid=d9bd652f-1700-0000-f04f-ac0e150e0000 pid=3605 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=d9bd652f-1700-0000-f04f-ac0e150e0000 pid=3605 execve guuid=0e5ee22f-1700-0000-f04f-ac0e180e0000 pid=3608 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0e5ee22f-1700-0000-f04f-ac0e180e0000 pid=3608 execve guuid=ff7e4330-1700-0000-f04f-ac0e1a0e0000 pid=3610 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ff7e4330-1700-0000-f04f-ac0e1a0e0000 pid=3610 execve guuid=46c0a530-1700-0000-f04f-ac0e1c0e0000 pid=3612 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=46c0a530-1700-0000-f04f-ac0e1c0e0000 pid=3612 execve guuid=1d010431-1700-0000-f04f-ac0e1e0e0000 pid=3614 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=1d010431-1700-0000-f04f-ac0e1e0e0000 pid=3614 execve guuid=b1b76831-1700-0000-f04f-ac0e210e0000 pid=3617 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=b1b76831-1700-0000-f04f-ac0e210e0000 pid=3617 execve guuid=9be9ca31-1700-0000-f04f-ac0e230e0000 pid=3619 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=9be9ca31-1700-0000-f04f-ac0e230e0000 pid=3619 execve guuid=de522f32-1700-0000-f04f-ac0e250e0000 pid=3621 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=de522f32-1700-0000-f04f-ac0e250e0000 pid=3621 execve guuid=7ff79632-1700-0000-f04f-ac0e270e0000 pid=3623 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=7ff79632-1700-0000-f04f-ac0e270e0000 pid=3623 execve guuid=a3f42033-1700-0000-f04f-ac0e2b0e0000 pid=3627 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a3f42033-1700-0000-f04f-ac0e2b0e0000 pid=3627 execve guuid=845c7633-1700-0000-f04f-ac0e2c0e0000 pid=3628 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=845c7633-1700-0000-f04f-ac0e2c0e0000 pid=3628 execve guuid=5a03d133-1700-0000-f04f-ac0e2e0e0000 pid=3630 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=5a03d133-1700-0000-f04f-ac0e2e0e0000 pid=3630 execve guuid=e6522b34-1700-0000-f04f-ac0e300e0000 pid=3632 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=e6522b34-1700-0000-f04f-ac0e300e0000 pid=3632 execve guuid=79d98d34-1700-0000-f04f-ac0e320e0000 pid=3634 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=79d98d34-1700-0000-f04f-ac0e320e0000 pid=3634 execve guuid=4763e534-1700-0000-f04f-ac0e350e0000 pid=3637 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=4763e534-1700-0000-f04f-ac0e350e0000 pid=3637 execve guuid=28e53b35-1700-0000-f04f-ac0e360e0000 pid=3638 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=28e53b35-1700-0000-f04f-ac0e360e0000 pid=3638 execve guuid=cc8ec935-1700-0000-f04f-ac0e390e0000 pid=3641 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=cc8ec935-1700-0000-f04f-ac0e390e0000 pid=3641 execve guuid=2e133036-1700-0000-f04f-ac0e3b0e0000 pid=3643 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=2e133036-1700-0000-f04f-ac0e3b0e0000 pid=3643 execve guuid=c4ed9836-1700-0000-f04f-ac0e3e0e0000 pid=3646 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=c4ed9836-1700-0000-f04f-ac0e3e0e0000 pid=3646 execve guuid=8cc3fe36-1700-0000-f04f-ac0e400e0000 pid=3648 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=8cc3fe36-1700-0000-f04f-ac0e400e0000 pid=3648 execve guuid=475a6337-1700-0000-f04f-ac0e420e0000 pid=3650 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=475a6337-1700-0000-f04f-ac0e420e0000 pid=3650 execve guuid=df15c537-1700-0000-f04f-ac0e450e0000 pid=3653 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=df15c537-1700-0000-f04f-ac0e450e0000 pid=3653 execve guuid=bc0d2438-1700-0000-f04f-ac0e470e0000 pid=3655 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=bc0d2438-1700-0000-f04f-ac0e470e0000 pid=3655 execve guuid=e8a38b38-1700-0000-f04f-ac0e480e0000 pid=3656 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=e8a38b38-1700-0000-f04f-ac0e480e0000 pid=3656 execve guuid=c649ee38-1700-0000-f04f-ac0e490e0000 pid=3657 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=c649ee38-1700-0000-f04f-ac0e490e0000 pid=3657 execve guuid=8c594839-1700-0000-f04f-ac0e4b0e0000 pid=3659 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=8c594839-1700-0000-f04f-ac0e4b0e0000 pid=3659 execve guuid=b3b2a139-1700-0000-f04f-ac0e4e0e0000 pid=3662 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=b3b2a139-1700-0000-f04f-ac0e4e0e0000 pid=3662 execve guuid=dafafb39-1700-0000-f04f-ac0e500e0000 pid=3664 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=dafafb39-1700-0000-f04f-ac0e500e0000 pid=3664 execve guuid=6e75533a-1700-0000-f04f-ac0e530e0000 pid=3667 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=6e75533a-1700-0000-f04f-ac0e530e0000 pid=3667 execve guuid=1196a93a-1700-0000-f04f-ac0e550e0000 pid=3669 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=1196a93a-1700-0000-f04f-ac0e550e0000 pid=3669 execve guuid=f84eff3a-1700-0000-f04f-ac0e580e0000 pid=3672 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=f84eff3a-1700-0000-f04f-ac0e580e0000 pid=3672 execve guuid=b5df553b-1700-0000-f04f-ac0e5a0e0000 pid=3674 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=b5df553b-1700-0000-f04f-ac0e5a0e0000 pid=3674 execve guuid=0753b23b-1700-0000-f04f-ac0e5c0e0000 pid=3676 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0753b23b-1700-0000-f04f-ac0e5c0e0000 pid=3676 execve guuid=85d5163c-1700-0000-f04f-ac0e600e0000 pid=3680 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=85d5163c-1700-0000-f04f-ac0e600e0000 pid=3680 execve guuid=0114763c-1700-0000-f04f-ac0e610e0000 pid=3681 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0114763c-1700-0000-f04f-ac0e610e0000 pid=3681 execve guuid=5633d43c-1700-0000-f04f-ac0e650e0000 pid=3685 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=5633d43c-1700-0000-f04f-ac0e650e0000 pid=3685 execve guuid=88603a3d-1700-0000-f04f-ac0e690e0000 pid=3689 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=88603a3d-1700-0000-f04f-ac0e690e0000 pid=3689 execve guuid=4a1b9a3d-1700-0000-f04f-ac0e6c0e0000 pid=3692 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=4a1b9a3d-1700-0000-f04f-ac0e6c0e0000 pid=3692 execve guuid=68a4f93d-1700-0000-f04f-ac0e6e0e0000 pid=3694 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=68a4f93d-1700-0000-f04f-ac0e6e0e0000 pid=3694 execve guuid=937b5a3e-1700-0000-f04f-ac0e720e0000 pid=3698 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=937b5a3e-1700-0000-f04f-ac0e720e0000 pid=3698 execve guuid=3f69bc3e-1700-0000-f04f-ac0e750e0000 pid=3701 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=3f69bc3e-1700-0000-f04f-ac0e750e0000 pid=3701 execve guuid=74791a3f-1700-0000-f04f-ac0e770e0000 pid=3703 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=74791a3f-1700-0000-f04f-ac0e770e0000 pid=3703 execve guuid=58e2793f-1700-0000-f04f-ac0e7a0e0000 pid=3706 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=58e2793f-1700-0000-f04f-ac0e7a0e0000 pid=3706 execve guuid=83b8db3f-1700-0000-f04f-ac0e7d0e0000 pid=3709 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=83b8db3f-1700-0000-f04f-ac0e7d0e0000 pid=3709 execve guuid=d0b12e40-1700-0000-f04f-ac0e7f0e0000 pid=3711 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=d0b12e40-1700-0000-f04f-ac0e7f0e0000 pid=3711 execve guuid=ef058840-1700-0000-f04f-ac0e800e0000 pid=3712 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ef058840-1700-0000-f04f-ac0e800e0000 pid=3712 execve guuid=342ee440-1700-0000-f04f-ac0e840e0000 pid=3716 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=342ee440-1700-0000-f04f-ac0e840e0000 pid=3716 execve guuid=bc763a41-1700-0000-f04f-ac0e880e0000 pid=3720 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=bc763a41-1700-0000-f04f-ac0e880e0000 pid=3720 execve guuid=4e2c9641-1700-0000-f04f-ac0e8a0e0000 pid=3722 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=4e2c9641-1700-0000-f04f-ac0e8a0e0000 pid=3722 execve guuid=8a46ef41-1700-0000-f04f-ac0e8c0e0000 pid=3724 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=8a46ef41-1700-0000-f04f-ac0e8c0e0000 pid=3724 execve guuid=bbad4742-1700-0000-f04f-ac0e8f0e0000 pid=3727 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=bbad4742-1700-0000-f04f-ac0e8f0e0000 pid=3727 execve guuid=966cab42-1700-0000-f04f-ac0e910e0000 pid=3729 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=966cab42-1700-0000-f04f-ac0e910e0000 pid=3729 execve guuid=e7b40c43-1700-0000-f04f-ac0e940e0000 pid=3732 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=e7b40c43-1700-0000-f04f-ac0e940e0000 pid=3732 execve guuid=a7797543-1700-0000-f04f-ac0e960e0000 pid=3734 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a7797543-1700-0000-f04f-ac0e960e0000 pid=3734 execve guuid=491ed943-1700-0000-f04f-ac0e9a0e0000 pid=3738 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=491ed943-1700-0000-f04f-ac0e9a0e0000 pid=3738 execve guuid=4ff63044-1700-0000-f04f-ac0e9e0e0000 pid=3742 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=4ff63044-1700-0000-f04f-ac0e9e0e0000 pid=3742 execve guuid=646a8e44-1700-0000-f04f-ac0ea00e0000 pid=3744 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=646a8e44-1700-0000-f04f-ac0ea00e0000 pid=3744 execve guuid=c47ef244-1700-0000-f04f-ac0ea20e0000 pid=3746 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=c47ef244-1700-0000-f04f-ac0ea20e0000 pid=3746 execve guuid=a7c64d45-1700-0000-f04f-ac0ea50e0000 pid=3749 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a7c64d45-1700-0000-f04f-ac0ea50e0000 pid=3749 execve guuid=a17fad45-1700-0000-f04f-ac0ea70e0000 pid=3751 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a17fad45-1700-0000-f04f-ac0ea70e0000 pid=3751 execve guuid=2ad60946-1700-0000-f04f-ac0ea90e0000 pid=3753 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=2ad60946-1700-0000-f04f-ac0ea90e0000 pid=3753 execve guuid=8ab96746-1700-0000-f04f-ac0eaa0e0000 pid=3754 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=8ab96746-1700-0000-f04f-ac0eaa0e0000 pid=3754 execve guuid=e4bfbb46-1700-0000-f04f-ac0eae0e0000 pid=3758 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=e4bfbb46-1700-0000-f04f-ac0eae0e0000 pid=3758 execve guuid=1fa41047-1700-0000-f04f-ac0eb20e0000 pid=3762 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=1fa41047-1700-0000-f04f-ac0eb20e0000 pid=3762 execve guuid=67386747-1700-0000-f04f-ac0eb30e0000 pid=3763 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=67386747-1700-0000-f04f-ac0eb30e0000 pid=3763 execve guuid=52a9bd47-1700-0000-f04f-ac0eb50e0000 pid=3765 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=52a9bd47-1700-0000-f04f-ac0eb50e0000 pid=3765 execve guuid=c8351a48-1700-0000-f04f-ac0eb80e0000 pid=3768 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=c8351a48-1700-0000-f04f-ac0eb80e0000 pid=3768 execve guuid=83d97148-1700-0000-f04f-ac0eba0e0000 pid=3770 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=83d97148-1700-0000-f04f-ac0eba0e0000 pid=3770 execve guuid=e34bcb48-1700-0000-f04f-ac0ebd0e0000 pid=3773 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=e34bcb48-1700-0000-f04f-ac0ebd0e0000 pid=3773 execve guuid=56bb1f49-1700-0000-f04f-ac0ebe0e0000 pid=3774 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=56bb1f49-1700-0000-f04f-ac0ebe0e0000 pid=3774 execve guuid=d5f27d49-1700-0000-f04f-ac0ec20e0000 pid=3778 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=d5f27d49-1700-0000-f04f-ac0ec20e0000 pid=3778 execve guuid=2d2fd949-1700-0000-f04f-ac0ec60e0000 pid=3782 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=2d2fd949-1700-0000-f04f-ac0ec60e0000 pid=3782 execve guuid=61cd364a-1700-0000-f04f-ac0ec80e0000 pid=3784 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=61cd364a-1700-0000-f04f-ac0ec80e0000 pid=3784 execve guuid=c61b954a-1700-0000-f04f-ac0eca0e0000 pid=3786 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=c61b954a-1700-0000-f04f-ac0eca0e0000 pid=3786 execve guuid=05a8ef4a-1700-0000-f04f-ac0ecc0e0000 pid=3788 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=05a8ef4a-1700-0000-f04f-ac0ecc0e0000 pid=3788 execve guuid=02c24d4b-1700-0000-f04f-ac0ecf0e0000 pid=3791 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=02c24d4b-1700-0000-f04f-ac0ecf0e0000 pid=3791 execve guuid=4e9aa74b-1700-0000-f04f-ac0ed10e0000 pid=3793 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=4e9aa74b-1700-0000-f04f-ac0ed10e0000 pid=3793 execve guuid=93a5fb4b-1700-0000-f04f-ac0ed30e0000 pid=3795 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=93a5fb4b-1700-0000-f04f-ac0ed30e0000 pid=3795 execve guuid=3709574c-1700-0000-f04f-ac0ed50e0000 pid=3797 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=3709574c-1700-0000-f04f-ac0ed50e0000 pid=3797 execve guuid=f3b2ae4c-1700-0000-f04f-ac0ed80e0000 pid=3800 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=f3b2ae4c-1700-0000-f04f-ac0ed80e0000 pid=3800 execve guuid=a8ae0f4d-1700-0000-f04f-ac0eda0e0000 pid=3802 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a8ae0f4d-1700-0000-f04f-ac0eda0e0000 pid=3802 execve guuid=536c6d4d-1700-0000-f04f-ac0edd0e0000 pid=3805 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=536c6d4d-1700-0000-f04f-ac0edd0e0000 pid=3805 execve guuid=0ca3cd4d-1700-0000-f04f-ac0edf0e0000 pid=3807 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0ca3cd4d-1700-0000-f04f-ac0edf0e0000 pid=3807 execve guuid=ce862a4e-1700-0000-f04f-ac0ee30e0000 pid=3811 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ce862a4e-1700-0000-f04f-ac0ee30e0000 pid=3811 execve guuid=9863804e-1700-0000-f04f-ac0ee60e0000 pid=3814 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=9863804e-1700-0000-f04f-ac0ee60e0000 pid=3814 execve guuid=86a4d24e-1700-0000-f04f-ac0ee80e0000 pid=3816 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=86a4d24e-1700-0000-f04f-ac0ee80e0000 pid=3816 execve guuid=6872284f-1700-0000-f04f-ac0eec0e0000 pid=3820 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=6872284f-1700-0000-f04f-ac0eec0e0000 pid=3820 execve guuid=ac757e4f-1700-0000-f04f-ac0ef00e0000 pid=3824 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ac757e4f-1700-0000-f04f-ac0ef00e0000 pid=3824 execve guuid=0525d54f-1700-0000-f04f-ac0ef30e0000 pid=3827 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=0525d54f-1700-0000-f04f-ac0ef30e0000 pid=3827 execve guuid=c0d62f50-1700-0000-f04f-ac0ef50e0000 pid=3829 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=c0d62f50-1700-0000-f04f-ac0ef50e0000 pid=3829 execve guuid=40a39150-1700-0000-f04f-ac0ef80e0000 pid=3832 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=40a39150-1700-0000-f04f-ac0ef80e0000 pid=3832 execve guuid=f489fb50-1700-0000-f04f-ac0efc0e0000 pid=3836 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=f489fb50-1700-0000-f04f-ac0efc0e0000 pid=3836 execve guuid=bdfc4e51-1700-0000-f04f-ac0e000f0000 pid=3840 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=bdfc4e51-1700-0000-f04f-ac0e000f0000 pid=3840 execve guuid=7cb3a851-1700-0000-f04f-ac0e020f0000 pid=3842 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=7cb3a851-1700-0000-f04f-ac0e020f0000 pid=3842 execve guuid=b492ff51-1700-0000-f04f-ac0e040f0000 pid=3844 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=b492ff51-1700-0000-f04f-ac0e040f0000 pid=3844 execve guuid=73295452-1700-0000-f04f-ac0e080f0000 pid=3848 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=73295452-1700-0000-f04f-ac0e080f0000 pid=3848 execve guuid=d3beac52-1700-0000-f04f-ac0e0c0f0000 pid=3852 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=d3beac52-1700-0000-f04f-ac0e0c0f0000 pid=3852 execve guuid=76c80753-1700-0000-f04f-ac0e0e0f0000 pid=3854 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=76c80753-1700-0000-f04f-ac0e0e0f0000 pid=3854 execve guuid=a1366353-1700-0000-f04f-ac0e100f0000 pid=3856 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a1366353-1700-0000-f04f-ac0e100f0000 pid=3856 execve guuid=f1a8bb53-1700-0000-f04f-ac0e140f0000 pid=3860 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=f1a8bb53-1700-0000-f04f-ac0e140f0000 pid=3860 execve guuid=de691454-1700-0000-f04f-ac0e180f0000 pid=3864 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=de691454-1700-0000-f04f-ac0e180f0000 pid=3864 execve guuid=e2076e54-1700-0000-f04f-ac0e1a0f0000 pid=3866 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=e2076e54-1700-0000-f04f-ac0e1a0f0000 pid=3866 execve guuid=640ace54-1700-0000-f04f-ac0e1c0f0000 pid=3868 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=640ace54-1700-0000-f04f-ac0e1c0f0000 pid=3868 execve guuid=f1812f55-1700-0000-f04f-ac0e200f0000 pid=3872 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=f1812f55-1700-0000-f04f-ac0e200f0000 pid=3872 execve guuid=16769855-1700-0000-f04f-ac0e240f0000 pid=3876 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=16769855-1700-0000-f04f-ac0e240f0000 pid=3876 execve guuid=32fbff55-1700-0000-f04f-ac0e270f0000 pid=3879 /usr/bin/ls guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=32fbff55-1700-0000-f04f-ac0e270f0000 pid=3879 execve guuid=91496256-1700-0000-f04f-ac0e2a0f0000 pid=3882 /usr/bin/rm guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=91496256-1700-0000-f04f-ac0e2a0f0000 pid=3882 execve guuid=184da056-1700-0000-f04f-ac0e2c0f0000 pid=3884 /usr/bin/wget net send-data write-file guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=184da056-1700-0000-f04f-ac0e2c0f0000 pid=3884 execve guuid=7830ff84-1700-0000-f04f-ac0ebd0f0000 pid=4029 /usr/bin/chmod guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=7830ff84-1700-0000-f04f-ac0ebd0f0000 pid=4029 execve guuid=6e273c85-1700-0000-f04f-ac0ebf0f0000 pid=4031 /usr/bin/dash guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=6e273c85-1700-0000-f04f-ac0ebf0f0000 pid=4031 clone guuid=bee11d86-1700-0000-f04f-ac0ec50f0000 pid=4037 /usr/bin/rm guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=bee11d86-1700-0000-f04f-ac0ec50f0000 pid=4037 execve guuid=ee548a86-1700-0000-f04f-ac0ec70f0000 pid=4039 /usr/bin/wget net send-data write-file guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ee548a86-1700-0000-f04f-ac0ec70f0000 pid=4039 execve guuid=a3f9afc8-1700-0000-f04f-ac0e85100000 pid=4229 /usr/bin/chmod guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=a3f9afc8-1700-0000-f04f-ac0e85100000 pid=4229 execve guuid=b2be6cc9-1700-0000-f04f-ac0e88100000 pid=4232 /usr/bin/dash guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=b2be6cc9-1700-0000-f04f-ac0e88100000 pid=4232 clone guuid=eda482cb-1700-0000-f04f-ac0e8e100000 pid=4238 /usr/bin/rm guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=eda482cb-1700-0000-f04f-ac0e8e100000 pid=4238 execve guuid=05d505cc-1700-0000-f04f-ac0e90100000 pid=4240 /usr/bin/wget net send-data write-file guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=05d505cc-1700-0000-f04f-ac0e90100000 pid=4240 execve guuid=aa0e8c4b-1800-0000-f04f-ac0ed5110000 pid=4565 /usr/bin/chmod guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=aa0e8c4b-1800-0000-f04f-ac0ed5110000 pid=4565 execve guuid=3000094c-1800-0000-f04f-ac0ed7110000 pid=4567 /usr/bin/dash guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=3000094c-1800-0000-f04f-ac0ed7110000 pid=4567 clone guuid=857f084d-1800-0000-f04f-ac0edd110000 pid=4573 /usr/bin/rm guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=857f084d-1800-0000-f04f-ac0edd110000 pid=4573 execve guuid=63eb7d4d-1800-0000-f04f-ac0ede110000 pid=4574 /usr/bin/wget net send-data write-file guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=63eb7d4d-1800-0000-f04f-ac0ede110000 pid=4574 execve guuid=b1bd74b9-1800-0000-f04f-ac0ec2120000 pid=4802 /usr/bin/chmod guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=b1bd74b9-1800-0000-f04f-ac0ec2120000 pid=4802 execve guuid=7c97f0b9-1800-0000-f04f-ac0ec3120000 pid=4803 /usr/bin/dash guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=7c97f0b9-1800-0000-f04f-ac0ec3120000 pid=4803 clone guuid=441741bc-1800-0000-f04f-ac0eca120000 pid=4810 /usr/bin/rm guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=441741bc-1800-0000-f04f-ac0eca120000 pid=4810 execve guuid=29dd91bc-1800-0000-f04f-ac0ecc120000 pid=4812 /usr/bin/wget net send-data write-file guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=29dd91bc-1800-0000-f04f-ac0ecc120000 pid=4812 execve guuid=ac4000d4-1800-0000-f04f-ac0e09130000 pid=4873 /usr/bin/chmod guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=ac4000d4-1800-0000-f04f-ac0e09130000 pid=4873 execve guuid=4bf36dd4-1800-0000-f04f-ac0e0b130000 pid=4875 /tmp/2ke2 guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=4bf36dd4-1800-0000-f04f-ac0e0b130000 pid=4875 execve guuid=62efb6d5-1800-0000-f04f-ac0e13130000 pid=4883 /usr/bin/rm delete-file guuid=9233352b-1700-0000-f04f-ac0efe0d0000 pid=3582->guuid=62efb6d5-1800-0000-f04f-ac0e13130000 pid=4883 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=184da056-1700-0000-f04f-ac0e2c0f0000 pid=3884->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=ee548a86-1700-0000-f04f-ac0ec70f0000 pid=4039->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=05d505cc-1700-0000-f04f-ac0e90100000 pid=4240->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=63eb7d4d-1800-0000-f04f-ac0ede110000 pid=4574->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=29dd91bc-1800-0000-f04f-ac0ecc120000 pid=4812->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-08 05:21:35 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 80e48530ea78b466d1e904ecd1ff403419aee4bc789af5eaa9ddef3476e05ec6

(this sample)

  
Delivery method
Distributed via web download

Comments