MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8681414fe4c9752e7d6b940aa84b6855187115d0ccb648b199f2362d126d630. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: a8681414fe4c9752e7d6b940aa84b6855187115d0ccb648b199f2362d126d630
SHA3-384 hash: 2df5b4aeba4fa498068212ebf1883bcced511561c26cf360b2d2bbbf32a3e4451ffcde72bee85a070627f9ce9ad16bb9
SHA1 hash: 089f28732cc6ee94ec77a674fe266663ea666a64
MD5 hash: bfd157f920d6926f793e79d40fe6bbd8
humanhash: quiet-stream-potato-summer
File name:kla.sh
Download: download sample
File size:810 bytes
First seen:2026-02-21 13:00:02 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:JC2ystDuWtCcBGuNCDphwOwOJ+zFP70vFvqMoFs3B5iCKkLyLJ+zFtQ:I2yYvdsaCbwOwOwzFP+qTczawzFtQ
TLSH T15701F1E5F8A1833270CC4C3FA19A849538C63A3F3550FC0814EBF975053CB99945E539
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=af6d8279-1600-0000-dc0d-36c5740c0000 pid=3188 /usr/bin/sudo guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194 /tmp/sample.bin guuid=af6d8279-1600-0000-dc0d-36c5740c0000 pid=3188->guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194 execve guuid=c1dd417c-1600-0000-dc0d-36c57d0c0000 pid=3197 /usr/bin/cp guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=c1dd417c-1600-0000-dc0d-36c57d0c0000 pid=3197 execve guuid=a35c8880-1600-0000-dc0d-36c5810c0000 pid=3201 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=a35c8880-1600-0000-dc0d-36c5810c0000 pid=3201 clone guuid=8f67b480-1600-0000-dc0d-36c5820c0000 pid=3202 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=8f67b480-1600-0000-dc0d-36c5820c0000 pid=3202 execve guuid=b15ab484-1600-0000-dc0d-36c5830c0000 pid=3203 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=b15ab484-1600-0000-dc0d-36c5830c0000 pid=3203 execve guuid=b5ad558d-1600-0000-dc0d-36c5840c0000 pid=3204 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=b5ad558d-1600-0000-dc0d-36c5840c0000 pid=3204 execve guuid=d722c38d-1600-0000-dc0d-36c5850c0000 pid=3205 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=d722c38d-1600-0000-dc0d-36c5850c0000 pid=3205 clone guuid=905e298e-1600-0000-dc0d-36c5860c0000 pid=3206 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=905e298e-1600-0000-dc0d-36c5860c0000 pid=3206 clone guuid=aa206a8e-1600-0000-dc0d-36c5870c0000 pid=3207 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=aa206a8e-1600-0000-dc0d-36c5870c0000 pid=3207 execve guuid=751cf990-1600-0000-dc0d-36c5880c0000 pid=3208 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=751cf990-1600-0000-dc0d-36c5880c0000 pid=3208 execve guuid=38737f94-1600-0000-dc0d-36c58e0c0000 pid=3214 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=38737f94-1600-0000-dc0d-36c58e0c0000 pid=3214 execve guuid=a98b7495-1600-0000-dc0d-36c5910c0000 pid=3217 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=a98b7495-1600-0000-dc0d-36c5910c0000 pid=3217 clone guuid=c996da95-1600-0000-dc0d-36c5930c0000 pid=3219 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=c996da95-1600-0000-dc0d-36c5930c0000 pid=3219 clone guuid=b4d80d96-1600-0000-dc0d-36c5950c0000 pid=3221 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=b4d80d96-1600-0000-dc0d-36c5950c0000 pid=3221 execve guuid=61d4399a-1600-0000-dc0d-36c5a20c0000 pid=3234 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=61d4399a-1600-0000-dc0d-36c5a20c0000 pid=3234 execve guuid=0885fca0-1600-0000-dc0d-36c5a60c0000 pid=3238 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=0885fca0-1600-0000-dc0d-36c5a60c0000 pid=3238 execve guuid=327f64a1-1600-0000-dc0d-36c5a80c0000 pid=3240 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=327f64a1-1600-0000-dc0d-36c5a80c0000 pid=3240 clone guuid=f3f4a0a1-1600-0000-dc0d-36c5aa0c0000 pid=3242 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=f3f4a0a1-1600-0000-dc0d-36c5aa0c0000 pid=3242 clone guuid=892ecea1-1600-0000-dc0d-36c5ab0c0000 pid=3243 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=892ecea1-1600-0000-dc0d-36c5ab0c0000 pid=3243 execve guuid=9fcd0ea4-1600-0000-dc0d-36c5ae0c0000 pid=3246 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=9fcd0ea4-1600-0000-dc0d-36c5ae0c0000 pid=3246 execve guuid=478f27a8-1600-0000-dc0d-36c5b20c0000 pid=3250 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=478f27a8-1600-0000-dc0d-36c5b20c0000 pid=3250 execve guuid=4ae1a6a8-1600-0000-dc0d-36c5b50c0000 pid=3253 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=4ae1a6a8-1600-0000-dc0d-36c5b50c0000 pid=3253 clone guuid=0e6b0aa9-1600-0000-dc0d-36c5b70c0000 pid=3255 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=0e6b0aa9-1600-0000-dc0d-36c5b70c0000 pid=3255 clone guuid=154d39a9-1600-0000-dc0d-36c5b80c0000 pid=3256 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=154d39a9-1600-0000-dc0d-36c5b80c0000 pid=3256 execve guuid=ad0a56ac-1600-0000-dc0d-36c5bd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=ad0a56ac-1600-0000-dc0d-36c5bd0c0000 pid=3261 execve guuid=690046b1-1600-0000-dc0d-36c5c20c0000 pid=3266 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=690046b1-1600-0000-dc0d-36c5c20c0000 pid=3266 execve guuid=b3b314b2-1600-0000-dc0d-36c5c30c0000 pid=3267 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=b3b314b2-1600-0000-dc0d-36c5c30c0000 pid=3267 clone guuid=69aa86b2-1600-0000-dc0d-36c5c40c0000 pid=3268 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=69aa86b2-1600-0000-dc0d-36c5c40c0000 pid=3268 clone guuid=fe47ccb2-1600-0000-dc0d-36c5c50c0000 pid=3269 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=fe47ccb2-1600-0000-dc0d-36c5c50c0000 pid=3269 execve guuid=fd8c06b6-1600-0000-dc0d-36c5cc0c0000 pid=3276 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=fd8c06b6-1600-0000-dc0d-36c5cc0c0000 pid=3276 execve guuid=9fc515ba-1600-0000-dc0d-36c5d90c0000 pid=3289 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=9fc515ba-1600-0000-dc0d-36c5d90c0000 pid=3289 execve guuid=a8748eba-1600-0000-dc0d-36c5db0c0000 pid=3291 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=a8748eba-1600-0000-dc0d-36c5db0c0000 pid=3291 clone guuid=6e04c8ba-1600-0000-dc0d-36c5dc0c0000 pid=3292 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=6e04c8ba-1600-0000-dc0d-36c5dc0c0000 pid=3292 clone guuid=369cefba-1600-0000-dc0d-36c5dd0c0000 pid=3293 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=369cefba-1600-0000-dc0d-36c5dd0c0000 pid=3293 execve guuid=a7584fbd-1600-0000-dc0d-36c5e50c0000 pid=3301 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=a7584fbd-1600-0000-dc0d-36c5e50c0000 pid=3301 execve guuid=3c8503c1-1600-0000-dc0d-36c5ee0c0000 pid=3310 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=3c8503c1-1600-0000-dc0d-36c5ee0c0000 pid=3310 execve guuid=c18a71c1-1600-0000-dc0d-36c5f00c0000 pid=3312 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=c18a71c1-1600-0000-dc0d-36c5f00c0000 pid=3312 clone guuid=8a5aacc1-1600-0000-dc0d-36c5f20c0000 pid=3314 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=8a5aacc1-1600-0000-dc0d-36c5f20c0000 pid=3314 clone guuid=f743d5c1-1600-0000-dc0d-36c5f30c0000 pid=3315 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=f743d5c1-1600-0000-dc0d-36c5f30c0000 pid=3315 execve guuid=c92822c5-1600-0000-dc0d-36c5fa0c0000 pid=3322 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=c92822c5-1600-0000-dc0d-36c5fa0c0000 pid=3322 execve guuid=300bf4c8-1600-0000-dc0d-36c5010d0000 pid=3329 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=300bf4c8-1600-0000-dc0d-36c5010d0000 pid=3329 execve guuid=ad4d59c9-1600-0000-dc0d-36c5030d0000 pid=3331 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=ad4d59c9-1600-0000-dc0d-36c5030d0000 pid=3331 clone guuid=09eb7bc9-1600-0000-dc0d-36c5040d0000 pid=3332 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=09eb7bc9-1600-0000-dc0d-36c5040d0000 pid=3332 clone guuid=19ea95c9-1600-0000-dc0d-36c5050d0000 pid=3333 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=19ea95c9-1600-0000-dc0d-36c5050d0000 pid=3333 execve guuid=9c50a9cb-1600-0000-dc0d-36c50c0d0000 pid=3340 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=9c50a9cb-1600-0000-dc0d-36c50c0d0000 pid=3340 execve guuid=19f209d0-1600-0000-dc0d-36c5170d0000 pid=3351 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=19f209d0-1600-0000-dc0d-36c5170d0000 pid=3351 execve guuid=fbde52d0-1600-0000-dc0d-36c5180d0000 pid=3352 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=fbde52d0-1600-0000-dc0d-36c5180d0000 pid=3352 clone guuid=5d6b7dd0-1600-0000-dc0d-36c51a0d0000 pid=3354 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=5d6b7dd0-1600-0000-dc0d-36c51a0d0000 pid=3354 clone guuid=53f8a1d0-1600-0000-dc0d-36c51b0d0000 pid=3355 /usr/bin/wget net send-data guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=53f8a1d0-1600-0000-dc0d-36c51b0d0000 pid=3355 execve guuid=dd8dd4d2-1600-0000-dc0d-36c5210d0000 pid=3361 /usr/bin/curl net send-data write-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=dd8dd4d2-1600-0000-dc0d-36c5210d0000 pid=3361 execve guuid=52a877d6-1600-0000-dc0d-36c5220d0000 pid=3362 /usr/bin/chmod guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=52a877d6-1600-0000-dc0d-36c5220d0000 pid=3362 execve guuid=34d1d6d6-1600-0000-dc0d-36c5230d0000 pid=3363 /usr/bin/bash guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=34d1d6d6-1600-0000-dc0d-36c5230d0000 pid=3363 clone guuid=fa541bd7-1600-0000-dc0d-36c5240d0000 pid=3364 /usr/bin/rm delete-file guuid=acbddb7b-1600-0000-dc0d-36c57a0c0000 pid=3194->guuid=fa541bd7-1600-0000-dc0d-36c5240d0000 pid=3364 execve cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 45.148.120.23:80 guuid=8f67b480-1600-0000-dc0d-36c5820c0000 pid=3202->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 136B guuid=b15ab484-1600-0000-dc0d-36c5830c0000 pid=3203->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 85B guuid=aa206a8e-1600-0000-dc0d-36c5870c0000 pid=3207->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=751cf990-1600-0000-dc0d-36c5880c0000 pid=3208->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=b4d80d96-1600-0000-dc0d-36c5950c0000 pid=3221->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=61d4399a-1600-0000-dc0d-36c5a20c0000 pid=3234->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=892ecea1-1600-0000-dc0d-36c5ab0c0000 pid=3243->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=9fcd0ea4-1600-0000-dc0d-36c5ae0c0000 pid=3246->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=154d39a9-1600-0000-dc0d-36c5b80c0000 pid=3256->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=ad0a56ac-1600-0000-dc0d-36c5bd0c0000 pid=3261->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=fe47ccb2-1600-0000-dc0d-36c5c50c0000 pid=3269->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=fd8c06b6-1600-0000-dc0d-36c5cc0c0000 pid=3276->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=369cefba-1600-0000-dc0d-36c5dd0c0000 pid=3293->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=a7584fbd-1600-0000-dc0d-36c5e50c0000 pid=3301->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=f743d5c1-1600-0000-dc0d-36c5f30c0000 pid=3315->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 136B guuid=c92822c5-1600-0000-dc0d-36c5fa0c0000 pid=3322->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 85B guuid=19ea95c9-1600-0000-dc0d-36c5050d0000 pid=3333->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 137B guuid=9c50a9cb-1600-0000-dc0d-36c50c0d0000 pid=3340->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 86B guuid=53f8a1d0-1600-0000-dc0d-36c51b0d0000 pid=3355->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 136B guuid=dd8dd4d2-1600-0000-dc0d-36c5210d0000 pid=3361->cb3920f1-a4d6-5cfa-ad1e-c149afc227b4 send: 85B
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2026-02-21 13:00:30 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a8681414fe4c9752e7d6b940aa84b6855187115d0ccb648b199f2362d126d630

(this sample)

  
Delivery method
Distributed via web download

Comments