MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9c9cc3cd47bec052002b0f73de3b801758688fe069cb7ae49c9e1bcce820e6c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 9c9cc3cd47bec052002b0f73de3b801758688fe069cb7ae49c9e1bcce820e6c5
SHA3-384 hash: 0798b982af1c1ab590671812f2abbef0063c00d77d366ffa494ea54450857b7e648bcd2f0d83065f23b67fcd0be79df0
SHA1 hash: 84dadc074437b7ba346a145d5c1eb9e96e77262f
MD5 hash: 218538688c2bfdc760de66c415a16d39
humanhash: ink-charlie-india-emma
File name:p
Download: download sample
File size:831 bytes
First seen:2026-06-18 07:07:22 UTC
Last seen:2026-06-18 20:29:43 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaC1NMxyN6FC529rj3AF07:e9Qp+MsC1NMdC5q3AG7
TLSH T193016FCB47506D00401A9E5E62D75290F821C3CE558B4B747F9C5D2EFBD8A14B137F94
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/tlDen/an/aua-wget
http://129.121.114.124/JBWn/an/aua-wget
http://129.121.114.124/P1Qn/an/aua-wget
http://129.121.114.124/D9qn/an/aua-wget
http://129.121.114.124/JMwn/an/aua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-18T04:14:00Z UTC
Last seen:
2026-06-18T06:49:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=5d1110aa-1a00-0000-fc75-3a50740a0000 pid=2676 /usr/bin/sudo guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683 /tmp/sample.bin write-file guuid=5d1110aa-1a00-0000-fc75-3a50740a0000 pid=2676->guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683 execve guuid=e2e8c4ac-1a00-0000-fc75-3a507c0a0000 pid=2684 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e2e8c4ac-1a00-0000-fc75-3a507c0a0000 pid=2684 execve guuid=a8e4e9ad-1a00-0000-fc75-3a507f0a0000 pid=2687 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=a8e4e9ad-1a00-0000-fc75-3a507f0a0000 pid=2687 execve guuid=a08f7bae-1a00-0000-fc75-3a50820a0000 pid=2690 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=a08f7bae-1a00-0000-fc75-3a50820a0000 pid=2690 execve guuid=e80109af-1a00-0000-fc75-3a50850a0000 pid=2693 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e80109af-1a00-0000-fc75-3a50850a0000 pid=2693 execve guuid=7a6e9eaf-1a00-0000-fc75-3a50870a0000 pid=2695 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7a6e9eaf-1a00-0000-fc75-3a50870a0000 pid=2695 execve guuid=8eac2bb0-1a00-0000-fc75-3a50890a0000 pid=2697 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=8eac2bb0-1a00-0000-fc75-3a50890a0000 pid=2697 execve guuid=575094b0-1a00-0000-fc75-3a508c0a0000 pid=2700 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=575094b0-1a00-0000-fc75-3a508c0a0000 pid=2700 execve guuid=bc8bb4b1-1a00-0000-fc75-3a508f0a0000 pid=2703 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=bc8bb4b1-1a00-0000-fc75-3a508f0a0000 pid=2703 execve guuid=09313bb2-1a00-0000-fc75-3a50900a0000 pid=2704 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=09313bb2-1a00-0000-fc75-3a50900a0000 pid=2704 execve guuid=d20cb4b2-1a00-0000-fc75-3a50920a0000 pid=2706 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d20cb4b2-1a00-0000-fc75-3a50920a0000 pid=2706 execve guuid=f69430b3-1a00-0000-fc75-3a50930a0000 pid=2707 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f69430b3-1a00-0000-fc75-3a50930a0000 pid=2707 execve guuid=ac7cacb3-1a00-0000-fc75-3a50950a0000 pid=2709 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=ac7cacb3-1a00-0000-fc75-3a50950a0000 pid=2709 execve guuid=17d041b4-1a00-0000-fc75-3a50960a0000 pid=2710 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=17d041b4-1a00-0000-fc75-3a50960a0000 pid=2710 execve guuid=8891e9b4-1a00-0000-fc75-3a50970a0000 pid=2711 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=8891e9b4-1a00-0000-fc75-3a50970a0000 pid=2711 execve guuid=0df49eb5-1a00-0000-fc75-3a50980a0000 pid=2712 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=0df49eb5-1a00-0000-fc75-3a50980a0000 pid=2712 execve guuid=792f2cb6-1a00-0000-fc75-3a509a0a0000 pid=2714 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=792f2cb6-1a00-0000-fc75-3a509a0a0000 pid=2714 execve guuid=dc50c9b6-1a00-0000-fc75-3a509d0a0000 pid=2717 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=dc50c9b6-1a00-0000-fc75-3a509d0a0000 pid=2717 execve guuid=158651b7-1a00-0000-fc75-3a509f0a0000 pid=2719 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=158651b7-1a00-0000-fc75-3a509f0a0000 pid=2719 execve guuid=2e05b5b7-1a00-0000-fc75-3a50a10a0000 pid=2721 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=2e05b5b7-1a00-0000-fc75-3a50a10a0000 pid=2721 execve guuid=de642fb8-1a00-0000-fc75-3a50a30a0000 pid=2723 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=de642fb8-1a00-0000-fc75-3a50a30a0000 pid=2723 execve guuid=d044adb8-1a00-0000-fc75-3a50a40a0000 pid=2724 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d044adb8-1a00-0000-fc75-3a50a40a0000 pid=2724 execve guuid=62ec2bb9-1a00-0000-fc75-3a50a50a0000 pid=2725 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=62ec2bb9-1a00-0000-fc75-3a50a50a0000 pid=2725 execve guuid=7cdce0b9-1a00-0000-fc75-3a50a60a0000 pid=2726 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7cdce0b9-1a00-0000-fc75-3a50a60a0000 pid=2726 execve guuid=bf4daeba-1a00-0000-fc75-3a50a70a0000 pid=2727 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=bf4daeba-1a00-0000-fc75-3a50a70a0000 pid=2727 execve guuid=4db870bb-1a00-0000-fc75-3a50a80a0000 pid=2728 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=4db870bb-1a00-0000-fc75-3a50a80a0000 pid=2728 execve guuid=ab921fbc-1a00-0000-fc75-3a50aa0a0000 pid=2730 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=ab921fbc-1a00-0000-fc75-3a50aa0a0000 pid=2730 execve guuid=9124e9bc-1a00-0000-fc75-3a50ab0a0000 pid=2731 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=9124e9bc-1a00-0000-fc75-3a50ab0a0000 pid=2731 execve guuid=6f2692bd-1a00-0000-fc75-3a50ac0a0000 pid=2732 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=6f2692bd-1a00-0000-fc75-3a50ac0a0000 pid=2732 execve guuid=273815be-1a00-0000-fc75-3a50af0a0000 pid=2735 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=273815be-1a00-0000-fc75-3a50af0a0000 pid=2735 execve guuid=50a896be-1a00-0000-fc75-3a50b20a0000 pid=2738 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=50a896be-1a00-0000-fc75-3a50b20a0000 pid=2738 execve guuid=8c3a1abf-1a00-0000-fc75-3a50b50a0000 pid=2741 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=8c3a1abf-1a00-0000-fc75-3a50b50a0000 pid=2741 execve guuid=84559cbf-1a00-0000-fc75-3a50b60a0000 pid=2742 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=84559cbf-1a00-0000-fc75-3a50b60a0000 pid=2742 execve guuid=a9c130c0-1a00-0000-fc75-3a50b80a0000 pid=2744 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=a9c130c0-1a00-0000-fc75-3a50b80a0000 pid=2744 execve guuid=4863bfc0-1a00-0000-fc75-3a50b90a0000 pid=2745 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=4863bfc0-1a00-0000-fc75-3a50b90a0000 pid=2745 execve guuid=89f93fc1-1a00-0000-fc75-3a50ba0a0000 pid=2746 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=89f93fc1-1a00-0000-fc75-3a50ba0a0000 pid=2746 execve guuid=09e0d6c1-1a00-0000-fc75-3a50bc0a0000 pid=2748 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=09e0d6c1-1a00-0000-fc75-3a50bc0a0000 pid=2748 execve guuid=b01271c2-1a00-0000-fc75-3a50bf0a0000 pid=2751 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=b01271c2-1a00-0000-fc75-3a50bf0a0000 pid=2751 execve guuid=49b1e3c2-1a00-0000-fc75-3a50c10a0000 pid=2753 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=49b1e3c2-1a00-0000-fc75-3a50c10a0000 pid=2753 execve guuid=3fb64fc3-1a00-0000-fc75-3a50c30a0000 pid=2755 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=3fb64fc3-1a00-0000-fc75-3a50c30a0000 pid=2755 execve guuid=f946bac3-1a00-0000-fc75-3a50c50a0000 pid=2757 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f946bac3-1a00-0000-fc75-3a50c50a0000 pid=2757 execve guuid=75aa21c4-1a00-0000-fc75-3a50c60a0000 pid=2758 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=75aa21c4-1a00-0000-fc75-3a50c60a0000 pid=2758 execve guuid=c5ab96c4-1a00-0000-fc75-3a50c80a0000 pid=2760 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=c5ab96c4-1a00-0000-fc75-3a50c80a0000 pid=2760 execve guuid=1af222c5-1a00-0000-fc75-3a50c90a0000 pid=2761 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=1af222c5-1a00-0000-fc75-3a50c90a0000 pid=2761 execve guuid=7f90a0c5-1a00-0000-fc75-3a50ca0a0000 pid=2762 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7f90a0c5-1a00-0000-fc75-3a50ca0a0000 pid=2762 execve guuid=c5b839c6-1a00-0000-fc75-3a50cd0a0000 pid=2765 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=c5b839c6-1a00-0000-fc75-3a50cd0a0000 pid=2765 execve guuid=7d70ccc6-1a00-0000-fc75-3a50d00a0000 pid=2768 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7d70ccc6-1a00-0000-fc75-3a50d00a0000 pid=2768 execve guuid=d95734c7-1a00-0000-fc75-3a50d10a0000 pid=2769 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d95734c7-1a00-0000-fc75-3a50d10a0000 pid=2769 execve guuid=6ed8d4c7-1a00-0000-fc75-3a50d40a0000 pid=2772 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=6ed8d4c7-1a00-0000-fc75-3a50d40a0000 pid=2772 execve guuid=0d5f39c8-1a00-0000-fc75-3a50d60a0000 pid=2774 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=0d5f39c8-1a00-0000-fc75-3a50d60a0000 pid=2774 execve guuid=a202a5c8-1a00-0000-fc75-3a50d70a0000 pid=2775 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=a202a5c8-1a00-0000-fc75-3a50d70a0000 pid=2775 execve guuid=e7163bc9-1a00-0000-fc75-3a50d80a0000 pid=2776 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e7163bc9-1a00-0000-fc75-3a50d80a0000 pid=2776 execve guuid=f651b1c9-1a00-0000-fc75-3a50d90a0000 pid=2777 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f651b1c9-1a00-0000-fc75-3a50d90a0000 pid=2777 execve guuid=26e719ca-1a00-0000-fc75-3a50db0a0000 pid=2779 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=26e719ca-1a00-0000-fc75-3a50db0a0000 pid=2779 execve guuid=40467dca-1a00-0000-fc75-3a50dd0a0000 pid=2781 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=40467dca-1a00-0000-fc75-3a50dd0a0000 pid=2781 execve guuid=66dc2dcb-1a00-0000-fc75-3a50e00a0000 pid=2784 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=66dc2dcb-1a00-0000-fc75-3a50e00a0000 pid=2784 execve guuid=1356d8cb-1a00-0000-fc75-3a50e30a0000 pid=2787 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=1356d8cb-1a00-0000-fc75-3a50e30a0000 pid=2787 execve guuid=bcb37acc-1a00-0000-fc75-3a50e70a0000 pid=2791 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=bcb37acc-1a00-0000-fc75-3a50e70a0000 pid=2791 execve guuid=51a827cd-1a00-0000-fc75-3a50e90a0000 pid=2793 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=51a827cd-1a00-0000-fc75-3a50e90a0000 pid=2793 execve guuid=17898dcd-1a00-0000-fc75-3a50eb0a0000 pid=2795 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=17898dcd-1a00-0000-fc75-3a50eb0a0000 pid=2795 execve guuid=15ba3ece-1a00-0000-fc75-3a50ee0a0000 pid=2798 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=15ba3ece-1a00-0000-fc75-3a50ee0a0000 pid=2798 execve guuid=221adbce-1a00-0000-fc75-3a50f10a0000 pid=2801 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=221adbce-1a00-0000-fc75-3a50f10a0000 pid=2801 execve guuid=0b997dcf-1a00-0000-fc75-3a50f40a0000 pid=2804 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=0b997dcf-1a00-0000-fc75-3a50f40a0000 pid=2804 execve guuid=790471d0-1a00-0000-fc75-3a50f50a0000 pid=2805 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=790471d0-1a00-0000-fc75-3a50f50a0000 pid=2805 execve guuid=f8306ed1-1a00-0000-fc75-3a50f60a0000 pid=2806 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f8306ed1-1a00-0000-fc75-3a50f60a0000 pid=2806 execve guuid=52248fd2-1a00-0000-fc75-3a50f70a0000 pid=2807 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=52248fd2-1a00-0000-fc75-3a50f70a0000 pid=2807 execve guuid=e89e4fd3-1a00-0000-fc75-3a50f90a0000 pid=2809 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e89e4fd3-1a00-0000-fc75-3a50f90a0000 pid=2809 execve guuid=479c40d4-1a00-0000-fc75-3a50fa0a0000 pid=2810 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=479c40d4-1a00-0000-fc75-3a50fa0a0000 pid=2810 execve guuid=7552f2d4-1a00-0000-fc75-3a50fc0a0000 pid=2812 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7552f2d4-1a00-0000-fc75-3a50fc0a0000 pid=2812 execve guuid=2309a4d5-1a00-0000-fc75-3a50fe0a0000 pid=2814 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=2309a4d5-1a00-0000-fc75-3a50fe0a0000 pid=2814 execve guuid=fd6648d6-1a00-0000-fc75-3a50000b0000 pid=2816 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=fd6648d6-1a00-0000-fc75-3a50000b0000 pid=2816 execve guuid=b024e8d6-1a00-0000-fc75-3a50030b0000 pid=2819 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=b024e8d6-1a00-0000-fc75-3a50030b0000 pid=2819 execve guuid=d7948ad7-1a00-0000-fc75-3a50050b0000 pid=2821 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d7948ad7-1a00-0000-fc75-3a50050b0000 pid=2821 execve guuid=0de312d8-1a00-0000-fc75-3a50060b0000 pid=2822 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=0de312d8-1a00-0000-fc75-3a50060b0000 pid=2822 execve guuid=82c2a0d8-1a00-0000-fc75-3a50080b0000 pid=2824 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=82c2a0d8-1a00-0000-fc75-3a50080b0000 pid=2824 execve guuid=35946bd9-1a00-0000-fc75-3a50090b0000 pid=2825 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=35946bd9-1a00-0000-fc75-3a50090b0000 pid=2825 execve guuid=62b03cda-1a00-0000-fc75-3a500a0b0000 pid=2826 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=62b03cda-1a00-0000-fc75-3a500a0b0000 pid=2826 execve guuid=9337bdda-1a00-0000-fc75-3a500b0b0000 pid=2827 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=9337bdda-1a00-0000-fc75-3a500b0b0000 pid=2827 execve guuid=380d40db-1a00-0000-fc75-3a500d0b0000 pid=2829 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=380d40db-1a00-0000-fc75-3a500d0b0000 pid=2829 execve guuid=5161bcdb-1a00-0000-fc75-3a500f0b0000 pid=2831 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=5161bcdb-1a00-0000-fc75-3a500f0b0000 pid=2831 execve guuid=30d935dc-1a00-0000-fc75-3a50110b0000 pid=2833 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=30d935dc-1a00-0000-fc75-3a50110b0000 pid=2833 execve guuid=76b2a1dc-1a00-0000-fc75-3a50130b0000 pid=2835 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=76b2a1dc-1a00-0000-fc75-3a50130b0000 pid=2835 execve guuid=3b371bdd-1a00-0000-fc75-3a50150b0000 pid=2837 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=3b371bdd-1a00-0000-fc75-3a50150b0000 pid=2837 execve guuid=bcb3a8dd-1a00-0000-fc75-3a50180b0000 pid=2840 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=bcb3a8dd-1a00-0000-fc75-3a50180b0000 pid=2840 execve guuid=5a320dde-1a00-0000-fc75-3a501a0b0000 pid=2842 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=5a320dde-1a00-0000-fc75-3a501a0b0000 pid=2842 execve guuid=63029bde-1a00-0000-fc75-3a501b0b0000 pid=2843 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=63029bde-1a00-0000-fc75-3a501b0b0000 pid=2843 execve guuid=81a113df-1a00-0000-fc75-3a501d0b0000 pid=2845 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=81a113df-1a00-0000-fc75-3a501d0b0000 pid=2845 execve guuid=e0c37fdf-1a00-0000-fc75-3a501e0b0000 pid=2846 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e0c37fdf-1a00-0000-fc75-3a501e0b0000 pid=2846 execve guuid=799e25e0-1a00-0000-fc75-3a50210b0000 pid=2849 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=799e25e0-1a00-0000-fc75-3a50210b0000 pid=2849 execve guuid=3a1ab5e0-1a00-0000-fc75-3a50240b0000 pid=2852 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=3a1ab5e0-1a00-0000-fc75-3a50240b0000 pid=2852 execve guuid=40ea25e1-1a00-0000-fc75-3a50260b0000 pid=2854 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=40ea25e1-1a00-0000-fc75-3a50260b0000 pid=2854 execve guuid=49a984e1-1a00-0000-fc75-3a50280b0000 pid=2856 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=49a984e1-1a00-0000-fc75-3a50280b0000 pid=2856 execve guuid=e643e3e1-1a00-0000-fc75-3a50290b0000 pid=2857 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e643e3e1-1a00-0000-fc75-3a50290b0000 pid=2857 execve guuid=a8d2a7e2-1a00-0000-fc75-3a502b0b0000 pid=2859 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=a8d2a7e2-1a00-0000-fc75-3a502b0b0000 pid=2859 execve guuid=3e7958e3-1a00-0000-fc75-3a502e0b0000 pid=2862 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=3e7958e3-1a00-0000-fc75-3a502e0b0000 pid=2862 execve guuid=87e9b5e3-1a00-0000-fc75-3a50300b0000 pid=2864 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=87e9b5e3-1a00-0000-fc75-3a50300b0000 pid=2864 execve guuid=f5890fe4-1a00-0000-fc75-3a50320b0000 pid=2866 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f5890fe4-1a00-0000-fc75-3a50320b0000 pid=2866 execve guuid=5bdc69e4-1a00-0000-fc75-3a50340b0000 pid=2868 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=5bdc69e4-1a00-0000-fc75-3a50340b0000 pid=2868 execve guuid=7006bfe4-1a00-0000-fc75-3a50360b0000 pid=2870 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7006bfe4-1a00-0000-fc75-3a50360b0000 pid=2870 execve guuid=da652be5-1a00-0000-fc75-3a50370b0000 pid=2871 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=da652be5-1a00-0000-fc75-3a50370b0000 pid=2871 execve guuid=42a0e6e5-1a00-0000-fc75-3a50390b0000 pid=2873 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=42a0e6e5-1a00-0000-fc75-3a50390b0000 pid=2873 execve guuid=cd3bc0e6-1a00-0000-fc75-3a503a0b0000 pid=2874 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=cd3bc0e6-1a00-0000-fc75-3a503a0b0000 pid=2874 execve guuid=229584e7-1a00-0000-fc75-3a503b0b0000 pid=2875 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=229584e7-1a00-0000-fc75-3a503b0b0000 pid=2875 execve guuid=f5f61fe8-1a00-0000-fc75-3a503d0b0000 pid=2877 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f5f61fe8-1a00-0000-fc75-3a503d0b0000 pid=2877 execve guuid=ca4b7fe8-1a00-0000-fc75-3a50400b0000 pid=2880 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=ca4b7fe8-1a00-0000-fc75-3a50400b0000 pid=2880 execve guuid=d7fbebe8-1a00-0000-fc75-3a50420b0000 pid=2882 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d7fbebe8-1a00-0000-fc75-3a50420b0000 pid=2882 execve guuid=920478e9-1a00-0000-fc75-3a50440b0000 pid=2884 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=920478e9-1a00-0000-fc75-3a50440b0000 pid=2884 execve guuid=01dc14ea-1a00-0000-fc75-3a50460b0000 pid=2886 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=01dc14ea-1a00-0000-fc75-3a50460b0000 pid=2886 execve guuid=d77592ea-1a00-0000-fc75-3a50480b0000 pid=2888 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d77592ea-1a00-0000-fc75-3a50480b0000 pid=2888 execve guuid=f46e07eb-1a00-0000-fc75-3a504a0b0000 pid=2890 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f46e07eb-1a00-0000-fc75-3a504a0b0000 pid=2890 execve guuid=5dc599eb-1a00-0000-fc75-3a504c0b0000 pid=2892 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=5dc599eb-1a00-0000-fc75-3a504c0b0000 pid=2892 execve guuid=f2b10fec-1a00-0000-fc75-3a504e0b0000 pid=2894 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f2b10fec-1a00-0000-fc75-3a504e0b0000 pid=2894 execve guuid=fa858eec-1a00-0000-fc75-3a50510b0000 pid=2897 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=fa858eec-1a00-0000-fc75-3a50510b0000 pid=2897 execve guuid=e4f8e7ec-1a00-0000-fc75-3a50530b0000 pid=2899 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e4f8e7ec-1a00-0000-fc75-3a50530b0000 pid=2899 execve guuid=c98740ed-1a00-0000-fc75-3a50540b0000 pid=2900 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=c98740ed-1a00-0000-fc75-3a50540b0000 pid=2900 execve guuid=b18ba0ed-1a00-0000-fc75-3a50560b0000 pid=2902 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=b18ba0ed-1a00-0000-fc75-3a50560b0000 pid=2902 execve guuid=f60d00ee-1a00-0000-fc75-3a50570b0000 pid=2903 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f60d00ee-1a00-0000-fc75-3a50570b0000 pid=2903 execve guuid=e3ad0fef-1a00-0000-fc75-3a505a0b0000 pid=2906 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e3ad0fef-1a00-0000-fc75-3a505a0b0000 pid=2906 execve guuid=893071ef-1a00-0000-fc75-3a505c0b0000 pid=2908 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=893071ef-1a00-0000-fc75-3a505c0b0000 pid=2908 execve guuid=19f4cfef-1a00-0000-fc75-3a505e0b0000 pid=2910 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=19f4cfef-1a00-0000-fc75-3a505e0b0000 pid=2910 execve guuid=de5048f0-1a00-0000-fc75-3a50610b0000 pid=2913 /usr/bin/ls guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=de5048f0-1a00-0000-fc75-3a50610b0000 pid=2913 execve guuid=f55cd0f0-1a00-0000-fc75-3a50630b0000 pid=2915 /usr/bin/rm guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f55cd0f0-1a00-0000-fc75-3a50630b0000 pid=2915 execve guuid=a4d518f1-1a00-0000-fc75-3a50640b0000 pid=2916 /usr/bin/wget net send-data write-file guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=a4d518f1-1a00-0000-fc75-3a50640b0000 pid=2916 execve guuid=8081a618-1b00-0000-fc75-3a50900b0000 pid=2960 /usr/bin/chmod guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=8081a618-1b00-0000-fc75-3a50900b0000 pid=2960 execve guuid=362de118-1b00-0000-fc75-3a50910b0000 pid=2961 /tmp/tlDe guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=362de118-1b00-0000-fc75-3a50910b0000 pid=2961 execve guuid=42f6921a-1b00-0000-fc75-3a50930b0000 pid=2963 /usr/bin/rm guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=42f6921a-1b00-0000-fc75-3a50930b0000 pid=2963 execve guuid=31b2d41a-1b00-0000-fc75-3a50940b0000 pid=2964 /usr/bin/wget net send-data write-file guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=31b2d41a-1b00-0000-fc75-3a50940b0000 pid=2964 execve guuid=f80d5c29-1b00-0000-fc75-3a50b00b0000 pid=2992 /usr/bin/chmod guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=f80d5c29-1b00-0000-fc75-3a50b00b0000 pid=2992 execve guuid=c52fb329-1b00-0000-fc75-3a50b10b0000 pid=2993 /tmp/JBW guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=c52fb329-1b00-0000-fc75-3a50b10b0000 pid=2993 execve guuid=00497f2a-1b00-0000-fc75-3a50b40b0000 pid=2996 /usr/bin/rm guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=00497f2a-1b00-0000-fc75-3a50b40b0000 pid=2996 execve guuid=c3e91a2b-1b00-0000-fc75-3a50b50b0000 pid=2997 /usr/bin/wget net send-data write-file guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=c3e91a2b-1b00-0000-fc75-3a50b50b0000 pid=2997 execve guuid=59be9e39-1b00-0000-fc75-3a50d30b0000 pid=3027 /usr/bin/chmod guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=59be9e39-1b00-0000-fc75-3a50d30b0000 pid=3027 execve guuid=4f34043a-1b00-0000-fc75-3a50d40b0000 pid=3028 /tmp/P1Q guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=4f34043a-1b00-0000-fc75-3a50d40b0000 pid=3028 execve guuid=7b08c73b-1b00-0000-fc75-3a50da0b0000 pid=3034 /usr/bin/rm guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7b08c73b-1b00-0000-fc75-3a50da0b0000 pid=3034 execve guuid=c4e12e3c-1b00-0000-fc75-3a50dc0b0000 pid=3036 /usr/bin/wget net send-data write-file guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=c4e12e3c-1b00-0000-fc75-3a50dc0b0000 pid=3036 execve guuid=76a4c94a-1b00-0000-fc75-3a50fe0b0000 pid=3070 /usr/bin/chmod guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=76a4c94a-1b00-0000-fc75-3a50fe0b0000 pid=3070 execve guuid=d941b24b-1b00-0000-fc75-3a50ff0b0000 pid=3071 /tmp/D9q guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=d941b24b-1b00-0000-fc75-3a50ff0b0000 pid=3071 execve guuid=7f1d9c4d-1b00-0000-fc75-3a50020c0000 pid=3074 /usr/bin/rm guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=7f1d9c4d-1b00-0000-fc75-3a50020c0000 pid=3074 execve guuid=62c4d84d-1b00-0000-fc75-3a50040c0000 pid=3076 /usr/bin/wget net send-data write-file guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=62c4d84d-1b00-0000-fc75-3a50040c0000 pid=3076 execve guuid=3824d55b-1b00-0000-fc75-3a502c0c0000 pid=3116 /usr/bin/chmod guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=3824d55b-1b00-0000-fc75-3a502c0c0000 pid=3116 execve guuid=e9e2215c-1b00-0000-fc75-3a502e0c0000 pid=3118 /tmp/JMw guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e9e2215c-1b00-0000-fc75-3a502e0c0000 pid=3118 execve guuid=e8e80b5d-1b00-0000-fc75-3a50320c0000 pid=3122 /usr/bin/rm delete-file guuid=8c6962ac-1a00-0000-fc75-3a507b0a0000 pid=2683->guuid=e8e80b5d-1b00-0000-fc75-3a50320c0000 pid=3122 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=a4d518f1-1a00-0000-fc75-3a50640b0000 pid=2916->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=31b2d41a-1b00-0000-fc75-3a50940b0000 pid=2964->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=c3e91a2b-1b00-0000-fc75-3a50b50b0000 pid=2997->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=c4e12e3c-1b00-0000-fc75-3a50dc0b0000 pid=3036->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=62c4d84d-1b00-0000-fc75-3a50040c0000 pid=3076->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-18 07:08:04 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9c9cc3cd47bec052002b0f73de3b801758688fe069cb7ae49c9e1bcce820e6c5

(this sample)

  
Delivery method
Distributed via web download

Comments