MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 839468f2fe4e29c76b2f28a2734d04294b107b4c73898718e6ea5083ec9a8063. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 839468f2fe4e29c76b2f28a2734d04294b107b4c73898718e6ea5083ec9a8063
SHA3-384 hash: c4a9f6d0850b0980b0b9ce4bb3ef38b15fa227e9d8e3cec495cfa0135a7589ec7740a7f0867f7652e136530b2ced6dd4
SHA1 hash: d0341c3f4d98eb96b825713b057fcb2c7645f1c1
MD5 hash: 242a10592fba06f3884c6d4e3fba4f83
humanhash: stairway-texas-arkansas-florida
File name:lil
Download: download sample
File size:848 bytes
First seen:2026-06-24 12:58:51 UTC
Last seen:2026-06-24 16:19:59 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkaXSCasaIWnChFo3FCsFnjCs6nljCS6KX:kXCKysE2hi0ziQvZohaXSJIaP1Lju+KX
TLSH T1D60148CA8410A90050AE9D6C22D75565F821D3CE198B4F69BF9C6D39ABE8D14F066F88
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/DWzdn/an/aelf ua-wge
http://129.121.114.124/uErn/an/aelf ua-wge
http://129.121.114.124/8Ffkn/an/aelf ua-wge
http://129.121.114.124/y7Vln/an/aelf ua-wge
http://129.121.114.124/xs3n/an/aelf ua-wge

Intelligence


File Origin
# of uploads :
2
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=9149beff-1800-0000-1f9d-2fc822140000 pid=5154 /usr/bin/sudo guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155 /tmp/sample.bin write-file guuid=9149beff-1800-0000-1f9d-2fc822140000 pid=5154->guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155 execve guuid=c087db01-1900-0000-1f9d-2fc824140000 pid=5156 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=c087db01-1900-0000-1f9d-2fc824140000 pid=5156 execve guuid=f35ab802-1900-0000-1f9d-2fc825140000 pid=5157 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f35ab802-1900-0000-1f9d-2fc825140000 pid=5157 execve guuid=5af02303-1900-0000-1f9d-2fc826140000 pid=5158 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=5af02303-1900-0000-1f9d-2fc826140000 pid=5158 execve guuid=c43c8c03-1900-0000-1f9d-2fc827140000 pid=5159 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=c43c8c03-1900-0000-1f9d-2fc827140000 pid=5159 execve guuid=11e5fa03-1900-0000-1f9d-2fc828140000 pid=5160 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=11e5fa03-1900-0000-1f9d-2fc828140000 pid=5160 execve guuid=9e577004-1900-0000-1f9d-2fc829140000 pid=5161 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=9e577004-1900-0000-1f9d-2fc829140000 pid=5161 execve guuid=bfc9dd04-1900-0000-1f9d-2fc82a140000 pid=5162 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=bfc9dd04-1900-0000-1f9d-2fc82a140000 pid=5162 execve guuid=cdae5305-1900-0000-1f9d-2fc82b140000 pid=5163 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=cdae5305-1900-0000-1f9d-2fc82b140000 pid=5163 execve guuid=b0b0c405-1900-0000-1f9d-2fc82c140000 pid=5164 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=b0b0c405-1900-0000-1f9d-2fc82c140000 pid=5164 execve guuid=882e3306-1900-0000-1f9d-2fc82d140000 pid=5165 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=882e3306-1900-0000-1f9d-2fc82d140000 pid=5165 execve guuid=ea19a206-1900-0000-1f9d-2fc82e140000 pid=5166 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ea19a206-1900-0000-1f9d-2fc82e140000 pid=5166 execve guuid=46cf1107-1900-0000-1f9d-2fc82f140000 pid=5167 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=46cf1107-1900-0000-1f9d-2fc82f140000 pid=5167 execve guuid=29a77a07-1900-0000-1f9d-2fc830140000 pid=5168 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=29a77a07-1900-0000-1f9d-2fc830140000 pid=5168 execve guuid=e0e1e907-1900-0000-1f9d-2fc831140000 pid=5169 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=e0e1e907-1900-0000-1f9d-2fc831140000 pid=5169 execve guuid=e2495d08-1900-0000-1f9d-2fc832140000 pid=5170 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=e2495d08-1900-0000-1f9d-2fc832140000 pid=5170 execve guuid=704fda08-1900-0000-1f9d-2fc833140000 pid=5171 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=704fda08-1900-0000-1f9d-2fc833140000 pid=5171 execve guuid=d5fa5109-1900-0000-1f9d-2fc834140000 pid=5172 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d5fa5109-1900-0000-1f9d-2fc834140000 pid=5172 execve guuid=1feaca09-1900-0000-1f9d-2fc835140000 pid=5173 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=1feaca09-1900-0000-1f9d-2fc835140000 pid=5173 execve guuid=0a683e0a-1900-0000-1f9d-2fc836140000 pid=5174 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0a683e0a-1900-0000-1f9d-2fc836140000 pid=5174 execve guuid=1c27b30a-1900-0000-1f9d-2fc837140000 pid=5175 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=1c27b30a-1900-0000-1f9d-2fc837140000 pid=5175 execve guuid=544e260b-1900-0000-1f9d-2fc838140000 pid=5176 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=544e260b-1900-0000-1f9d-2fc838140000 pid=5176 execve guuid=e618ac0b-1900-0000-1f9d-2fc839140000 pid=5177 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=e618ac0b-1900-0000-1f9d-2fc839140000 pid=5177 execve guuid=58f5200c-1900-0000-1f9d-2fc83a140000 pid=5178 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=58f5200c-1900-0000-1f9d-2fc83a140000 pid=5178 execve guuid=e9b6940c-1900-0000-1f9d-2fc83b140000 pid=5179 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=e9b6940c-1900-0000-1f9d-2fc83b140000 pid=5179 execve guuid=ab30070d-1900-0000-1f9d-2fc83c140000 pid=5180 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ab30070d-1900-0000-1f9d-2fc83c140000 pid=5180 execve guuid=6b53800d-1900-0000-1f9d-2fc83d140000 pid=5181 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=6b53800d-1900-0000-1f9d-2fc83d140000 pid=5181 execve guuid=b567fa0d-1900-0000-1f9d-2fc83e140000 pid=5182 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=b567fa0d-1900-0000-1f9d-2fc83e140000 pid=5182 execve guuid=575d840e-1900-0000-1f9d-2fc83f140000 pid=5183 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=575d840e-1900-0000-1f9d-2fc83f140000 pid=5183 execve guuid=3f79120f-1900-0000-1f9d-2fc840140000 pid=5184 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3f79120f-1900-0000-1f9d-2fc840140000 pid=5184 execve guuid=24898e0f-1900-0000-1f9d-2fc841140000 pid=5185 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=24898e0f-1900-0000-1f9d-2fc841140000 pid=5185 execve guuid=d21b0f10-1900-0000-1f9d-2fc842140000 pid=5186 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d21b0f10-1900-0000-1f9d-2fc842140000 pid=5186 execve guuid=90498a10-1900-0000-1f9d-2fc843140000 pid=5187 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=90498a10-1900-0000-1f9d-2fc843140000 pid=5187 execve guuid=186d0611-1900-0000-1f9d-2fc844140000 pid=5188 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=186d0611-1900-0000-1f9d-2fc844140000 pid=5188 execve guuid=c3fe8b11-1900-0000-1f9d-2fc845140000 pid=5189 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=c3fe8b11-1900-0000-1f9d-2fc845140000 pid=5189 execve guuid=929e0b12-1900-0000-1f9d-2fc846140000 pid=5190 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=929e0b12-1900-0000-1f9d-2fc846140000 pid=5190 execve guuid=63a58212-1900-0000-1f9d-2fc847140000 pid=5191 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=63a58212-1900-0000-1f9d-2fc847140000 pid=5191 execve guuid=61f54913-1900-0000-1f9d-2fc848140000 pid=5192 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=61f54913-1900-0000-1f9d-2fc848140000 pid=5192 execve guuid=3574c213-1900-0000-1f9d-2fc849140000 pid=5193 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3574c213-1900-0000-1f9d-2fc849140000 pid=5193 execve guuid=3aa23e14-1900-0000-1f9d-2fc84a140000 pid=5194 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3aa23e14-1900-0000-1f9d-2fc84a140000 pid=5194 execve guuid=3b33c214-1900-0000-1f9d-2fc84b140000 pid=5195 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3b33c214-1900-0000-1f9d-2fc84b140000 pid=5195 execve guuid=d4fa3c15-1900-0000-1f9d-2fc84c140000 pid=5196 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d4fa3c15-1900-0000-1f9d-2fc84c140000 pid=5196 execve guuid=81a1bb15-1900-0000-1f9d-2fc84d140000 pid=5197 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=81a1bb15-1900-0000-1f9d-2fc84d140000 pid=5197 execve guuid=644d4016-1900-0000-1f9d-2fc84e140000 pid=5198 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=644d4016-1900-0000-1f9d-2fc84e140000 pid=5198 execve guuid=d266c616-1900-0000-1f9d-2fc84f140000 pid=5199 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d266c616-1900-0000-1f9d-2fc84f140000 pid=5199 execve guuid=f83d4117-1900-0000-1f9d-2fc850140000 pid=5200 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f83d4117-1900-0000-1f9d-2fc850140000 pid=5200 execve guuid=7d3eb317-1900-0000-1f9d-2fc851140000 pid=5201 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=7d3eb317-1900-0000-1f9d-2fc851140000 pid=5201 execve guuid=4f132b18-1900-0000-1f9d-2fc852140000 pid=5202 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=4f132b18-1900-0000-1f9d-2fc852140000 pid=5202 execve guuid=59c9a518-1900-0000-1f9d-2fc853140000 pid=5203 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=59c9a518-1900-0000-1f9d-2fc853140000 pid=5203 execve guuid=31511f19-1900-0000-1f9d-2fc854140000 pid=5204 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=31511f19-1900-0000-1f9d-2fc854140000 pid=5204 execve guuid=38869619-1900-0000-1f9d-2fc855140000 pid=5205 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=38869619-1900-0000-1f9d-2fc855140000 pid=5205 execve guuid=572f691a-1900-0000-1f9d-2fc856140000 pid=5206 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=572f691a-1900-0000-1f9d-2fc856140000 pid=5206 execve guuid=0b84e61a-1900-0000-1f9d-2fc857140000 pid=5207 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0b84e61a-1900-0000-1f9d-2fc857140000 pid=5207 execve guuid=6d30821b-1900-0000-1f9d-2fc858140000 pid=5208 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=6d30821b-1900-0000-1f9d-2fc858140000 pid=5208 execve guuid=70daf41b-1900-0000-1f9d-2fc859140000 pid=5209 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=70daf41b-1900-0000-1f9d-2fc859140000 pid=5209 execve guuid=29b4641c-1900-0000-1f9d-2fc85a140000 pid=5210 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=29b4641c-1900-0000-1f9d-2fc85a140000 pid=5210 execve guuid=3a4bda1c-1900-0000-1f9d-2fc85b140000 pid=5211 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3a4bda1c-1900-0000-1f9d-2fc85b140000 pid=5211 execve guuid=3c09511d-1900-0000-1f9d-2fc85c140000 pid=5212 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3c09511d-1900-0000-1f9d-2fc85c140000 pid=5212 execve guuid=da6fcc1d-1900-0000-1f9d-2fc85d140000 pid=5213 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=da6fcc1d-1900-0000-1f9d-2fc85d140000 pid=5213 execve guuid=9f18481e-1900-0000-1f9d-2fc85e140000 pid=5214 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=9f18481e-1900-0000-1f9d-2fc85e140000 pid=5214 execve guuid=bf45c11e-1900-0000-1f9d-2fc85f140000 pid=5215 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=bf45c11e-1900-0000-1f9d-2fc85f140000 pid=5215 execve guuid=9d9c351f-1900-0000-1f9d-2fc860140000 pid=5216 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=9d9c351f-1900-0000-1f9d-2fc860140000 pid=5216 execve guuid=db66b21f-1900-0000-1f9d-2fc861140000 pid=5217 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=db66b21f-1900-0000-1f9d-2fc861140000 pid=5217 execve guuid=a9da3120-1900-0000-1f9d-2fc862140000 pid=5218 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=a9da3120-1900-0000-1f9d-2fc862140000 pid=5218 execve guuid=0f4eb920-1900-0000-1f9d-2fc863140000 pid=5219 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0f4eb920-1900-0000-1f9d-2fc863140000 pid=5219 execve guuid=91af3121-1900-0000-1f9d-2fc864140000 pid=5220 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=91af3121-1900-0000-1f9d-2fc864140000 pid=5220 execve guuid=1251ac21-1900-0000-1f9d-2fc865140000 pid=5221 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=1251ac21-1900-0000-1f9d-2fc865140000 pid=5221 execve guuid=a0ff2422-1900-0000-1f9d-2fc866140000 pid=5222 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=a0ff2422-1900-0000-1f9d-2fc866140000 pid=5222 execve guuid=af729422-1900-0000-1f9d-2fc867140000 pid=5223 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=af729422-1900-0000-1f9d-2fc867140000 pid=5223 execve guuid=1f670223-1900-0000-1f9d-2fc868140000 pid=5224 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=1f670223-1900-0000-1f9d-2fc868140000 pid=5224 execve guuid=e8476f23-1900-0000-1f9d-2fc869140000 pid=5225 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=e8476f23-1900-0000-1f9d-2fc869140000 pid=5225 execve guuid=ca3eda23-1900-0000-1f9d-2fc86a140000 pid=5226 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ca3eda23-1900-0000-1f9d-2fc86a140000 pid=5226 execve guuid=ab2b5424-1900-0000-1f9d-2fc86b140000 pid=5227 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ab2b5424-1900-0000-1f9d-2fc86b140000 pid=5227 execve guuid=512ecd24-1900-0000-1f9d-2fc86c140000 pid=5228 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=512ecd24-1900-0000-1f9d-2fc86c140000 pid=5228 execve guuid=d9784625-1900-0000-1f9d-2fc86d140000 pid=5229 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d9784625-1900-0000-1f9d-2fc86d140000 pid=5229 execve guuid=0d99b925-1900-0000-1f9d-2fc86e140000 pid=5230 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0d99b925-1900-0000-1f9d-2fc86e140000 pid=5230 execve guuid=52b23226-1900-0000-1f9d-2fc86f140000 pid=5231 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=52b23226-1900-0000-1f9d-2fc86f140000 pid=5231 execve guuid=4d4faa26-1900-0000-1f9d-2fc870140000 pid=5232 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=4d4faa26-1900-0000-1f9d-2fc870140000 pid=5232 execve guuid=f4782127-1900-0000-1f9d-2fc871140000 pid=5233 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f4782127-1900-0000-1f9d-2fc871140000 pid=5233 execve guuid=1bbfc827-1900-0000-1f9d-2fc872140000 pid=5234 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=1bbfc827-1900-0000-1f9d-2fc872140000 pid=5234 execve guuid=ebce4928-1900-0000-1f9d-2fc873140000 pid=5235 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ebce4928-1900-0000-1f9d-2fc873140000 pid=5235 execve guuid=04ffc628-1900-0000-1f9d-2fc874140000 pid=5236 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=04ffc628-1900-0000-1f9d-2fc874140000 pid=5236 execve guuid=08354429-1900-0000-1f9d-2fc875140000 pid=5237 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=08354429-1900-0000-1f9d-2fc875140000 pid=5237 execve guuid=005ec029-1900-0000-1f9d-2fc876140000 pid=5238 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=005ec029-1900-0000-1f9d-2fc876140000 pid=5238 execve guuid=908c332a-1900-0000-1f9d-2fc877140000 pid=5239 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=908c332a-1900-0000-1f9d-2fc877140000 pid=5239 execve guuid=a8b49c2a-1900-0000-1f9d-2fc878140000 pid=5240 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=a8b49c2a-1900-0000-1f9d-2fc878140000 pid=5240 execve guuid=bf1a062b-1900-0000-1f9d-2fc879140000 pid=5241 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=bf1a062b-1900-0000-1f9d-2fc879140000 pid=5241 execve guuid=5e52742b-1900-0000-1f9d-2fc87a140000 pid=5242 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=5e52742b-1900-0000-1f9d-2fc87a140000 pid=5242 execve guuid=476de22b-1900-0000-1f9d-2fc87b140000 pid=5243 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=476de22b-1900-0000-1f9d-2fc87b140000 pid=5243 execve guuid=d99b532c-1900-0000-1f9d-2fc87c140000 pid=5244 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d99b532c-1900-0000-1f9d-2fc87c140000 pid=5244 execve guuid=d8b8d12c-1900-0000-1f9d-2fc87d140000 pid=5245 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=d8b8d12c-1900-0000-1f9d-2fc87d140000 pid=5245 execve guuid=af2d542d-1900-0000-1f9d-2fc87e140000 pid=5246 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=af2d542d-1900-0000-1f9d-2fc87e140000 pid=5246 execve guuid=5b84dd2d-1900-0000-1f9d-2fc87f140000 pid=5247 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=5b84dd2d-1900-0000-1f9d-2fc87f140000 pid=5247 execve guuid=f6b5642e-1900-0000-1f9d-2fc880140000 pid=5248 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f6b5642e-1900-0000-1f9d-2fc880140000 pid=5248 execve guuid=6aa0ed2e-1900-0000-1f9d-2fc881140000 pid=5249 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=6aa0ed2e-1900-0000-1f9d-2fc881140000 pid=5249 execve guuid=44b4792f-1900-0000-1f9d-2fc882140000 pid=5250 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=44b4792f-1900-0000-1f9d-2fc882140000 pid=5250 execve guuid=ddc4fc2f-1900-0000-1f9d-2fc883140000 pid=5251 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ddc4fc2f-1900-0000-1f9d-2fc883140000 pid=5251 execve guuid=601b7e30-1900-0000-1f9d-2fc884140000 pid=5252 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=601b7e30-1900-0000-1f9d-2fc884140000 pid=5252 execve guuid=81017531-1900-0000-1f9d-2fc885140000 pid=5253 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=81017531-1900-0000-1f9d-2fc885140000 pid=5253 execve guuid=81650d33-1900-0000-1f9d-2fc886140000 pid=5254 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=81650d33-1900-0000-1f9d-2fc886140000 pid=5254 execve guuid=0431d433-1900-0000-1f9d-2fc887140000 pid=5255 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0431d433-1900-0000-1f9d-2fc887140000 pid=5255 execve guuid=413dbb34-1900-0000-1f9d-2fc888140000 pid=5256 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=413dbb34-1900-0000-1f9d-2fc888140000 pid=5256 execve guuid=3b108c35-1900-0000-1f9d-2fc889140000 pid=5257 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3b108c35-1900-0000-1f9d-2fc889140000 pid=5257 execve guuid=7f0b4236-1900-0000-1f9d-2fc88a140000 pid=5258 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=7f0b4236-1900-0000-1f9d-2fc88a140000 pid=5258 execve guuid=6b9eec36-1900-0000-1f9d-2fc88b140000 pid=5259 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=6b9eec36-1900-0000-1f9d-2fc88b140000 pid=5259 execve guuid=f4fe8e37-1900-0000-1f9d-2fc88c140000 pid=5260 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f4fe8e37-1900-0000-1f9d-2fc88c140000 pid=5260 execve guuid=10972738-1900-0000-1f9d-2fc88d140000 pid=5261 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=10972738-1900-0000-1f9d-2fc88d140000 pid=5261 execve guuid=4e816639-1900-0000-1f9d-2fc88e140000 pid=5262 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=4e816639-1900-0000-1f9d-2fc88e140000 pid=5262 execve guuid=c9d3193a-1900-0000-1f9d-2fc88f140000 pid=5263 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=c9d3193a-1900-0000-1f9d-2fc88f140000 pid=5263 execve guuid=cebda13a-1900-0000-1f9d-2fc890140000 pid=5264 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=cebda13a-1900-0000-1f9d-2fc890140000 pid=5264 execve guuid=e2b9283b-1900-0000-1f9d-2fc891140000 pid=5265 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=e2b9283b-1900-0000-1f9d-2fc891140000 pid=5265 execve guuid=7187b53b-1900-0000-1f9d-2fc892140000 pid=5266 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=7187b53b-1900-0000-1f9d-2fc892140000 pid=5266 execve guuid=bd61723c-1900-0000-1f9d-2fc893140000 pid=5267 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=bd61723c-1900-0000-1f9d-2fc893140000 pid=5267 execve guuid=ff823b3d-1900-0000-1f9d-2fc894140000 pid=5268 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=ff823b3d-1900-0000-1f9d-2fc894140000 pid=5268 execve guuid=9a94083e-1900-0000-1f9d-2fc895140000 pid=5269 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=9a94083e-1900-0000-1f9d-2fc895140000 pid=5269 execve guuid=3986bf3e-1900-0000-1f9d-2fc896140000 pid=5270 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3986bf3e-1900-0000-1f9d-2fc896140000 pid=5270 execve guuid=b140b63f-1900-0000-1f9d-2fc897140000 pid=5271 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=b140b63f-1900-0000-1f9d-2fc897140000 pid=5271 execve guuid=8b448040-1900-0000-1f9d-2fc898140000 pid=5272 /usr/bin/ls guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=8b448040-1900-0000-1f9d-2fc898140000 pid=5272 execve guuid=5b1d4b41-1900-0000-1f9d-2fc899140000 pid=5273 /usr/bin/rm guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=5b1d4b41-1900-0000-1f9d-2fc899140000 pid=5273 execve guuid=f3b9b541-1900-0000-1f9d-2fc89a140000 pid=5274 /usr/bin/wget net send-data write-file guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f3b9b541-1900-0000-1f9d-2fc89a140000 pid=5274 execve guuid=80407d7d-1900-0000-1f9d-2fc89b140000 pid=5275 /usr/bin/chmod guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=80407d7d-1900-0000-1f9d-2fc89b140000 pid=5275 execve guuid=093fcf7d-1900-0000-1f9d-2fc89c140000 pid=5276 /usr/bin/dash guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=093fcf7d-1900-0000-1f9d-2fc89c140000 pid=5276 clone guuid=3003917e-1900-0000-1f9d-2fc89e140000 pid=5278 /usr/bin/rm guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3003917e-1900-0000-1f9d-2fc89e140000 pid=5278 execve guuid=f2c1b97f-1900-0000-1f9d-2fc89f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=f2c1b97f-1900-0000-1f9d-2fc89f140000 pid=5279 execve guuid=80316e98-1900-0000-1f9d-2fc8a0140000 pid=5280 /usr/bin/chmod guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=80316e98-1900-0000-1f9d-2fc8a0140000 pid=5280 execve guuid=5d04c198-1900-0000-1f9d-2fc8a1140000 pid=5281 /usr/bin/dash guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=5d04c198-1900-0000-1f9d-2fc8a1140000 pid=5281 clone guuid=dc8f5d99-1900-0000-1f9d-2fc8a3140000 pid=5283 /usr/bin/rm guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=dc8f5d99-1900-0000-1f9d-2fc8a3140000 pid=5283 execve guuid=0dffc899-1900-0000-1f9d-2fc8a4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0dffc899-1900-0000-1f9d-2fc8a4140000 pid=5284 execve guuid=9e3e41b9-1900-0000-1f9d-2fc8ac140000 pid=5292 /usr/bin/chmod guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=9e3e41b9-1900-0000-1f9d-2fc8ac140000 pid=5292 execve guuid=0596f2b9-1900-0000-1f9d-2fc8ad140000 pid=5293 /usr/bin/dash guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=0596f2b9-1900-0000-1f9d-2fc8ad140000 pid=5293 clone guuid=60bb7cbb-1900-0000-1f9d-2fc8af140000 pid=5295 /usr/bin/rm guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=60bb7cbb-1900-0000-1f9d-2fc8af140000 pid=5295 execve guuid=abe63abc-1900-0000-1f9d-2fc8b0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=abe63abc-1900-0000-1f9d-2fc8b0140000 pid=5296 execve guuid=401e69de-1900-0000-1f9d-2fc8b1140000 pid=5297 /usr/bin/chmod guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=401e69de-1900-0000-1f9d-2fc8b1140000 pid=5297 execve guuid=8558f3de-1900-0000-1f9d-2fc8b2140000 pid=5298 /usr/bin/dash guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=8558f3de-1900-0000-1f9d-2fc8b2140000 pid=5298 clone guuid=b01c9de0-1900-0000-1f9d-2fc8b4140000 pid=5300 /usr/bin/rm guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=b01c9de0-1900-0000-1f9d-2fc8b4140000 pid=5300 execve guuid=5cc6f9e1-1900-0000-1f9d-2fc8b5140000 pid=5301 /usr/bin/wget net send-data write-file guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=5cc6f9e1-1900-0000-1f9d-2fc8b5140000 pid=5301 execve guuid=3e9e560e-1a00-0000-1f9d-2fc8b6140000 pid=5302 /usr/bin/chmod guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=3e9e560e-1a00-0000-1f9d-2fc8b6140000 pid=5302 execve guuid=7934de0e-1a00-0000-1f9d-2fc8b7140000 pid=5303 /usr/bin/dash guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=7934de0e-1a00-0000-1f9d-2fc8b7140000 pid=5303 clone guuid=630a4711-1a00-0000-1f9d-2fc8b9140000 pid=5305 /usr/bin/rm delete-file guuid=1d6f9401-1900-0000-1f9d-2fc823140000 pid=5155->guuid=630a4711-1a00-0000-1f9d-2fc8b9140000 pid=5305 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=f3b9b541-1900-0000-1f9d-2fc89a140000 pid=5274->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=f2c1b97f-1900-0000-1f9d-2fc89f140000 pid=5279->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=0dffc899-1900-0000-1f9d-2fc8a4140000 pid=5284->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=abe63abc-1900-0000-1f9d-2fc8b0140000 pid=5296->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=5cc6f9e1-1900-0000-1f9d-2fc8b5140000 pid=5301->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 839468f2fe4e29c76b2f28a2734d04294b107b4c73898718e6ea5083ec9a8063

(this sample)

  
Delivery method
Distributed via web download

Comments