🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 be6251b0a4cf2d5f0d2eac02caaf5fe1def80a215561d355a44528f32d881cf5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: be6251b0a4cf2d5f0d2eac02caaf5fe1def80a215561d355a44528f32d881cf5
SHA3-384 hash: 827c8f1b0b93bcc360625f6454ff62746920708da88d0d71f2c27c0ad3a635452f8c8924808a39bb3ab333c15b95ea32
SHA1 hash: 7bff6b70a1e5fcc2ba221854999bf4b17ea23352
MD5 hash: 6fc94f5c2f03ec2a0bc4ba1c35b37b0c
humanhash: ceiling-green-salami-lamp
File name:kla.sh
Download: download sample
File size:2'289 bytes
First seen:2026-10-06 04:40:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:H6vdV+SAWS6T16TO6TjE6Ta6TWRQTFjoTsiAGWK94nmpJL3EOnTGwQHJKm:H6vmLWS+laERvSoMGWK2UJo26pz
TLSH T10E41CCF3F9B49C31F429842CFB4EA2E579935D7F41E0A85A84AB7911AE5C01A60DDF30
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=5fd712e8-1600-0000-f112-78f1dc0d0000 pid=3548 /usr/bin/sudo guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553 /tmp/sample.bin guuid=5fd712e8-1600-0000-f112-78f1dc0d0000 pid=3548->guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553 execve guuid=32c1ccea-1600-0000-f112-78f1e20d0000 pid=3554 /usr/bin/uname guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553->guuid=32c1ccea-1600-0000-f112-78f1e20d0000 pid=3554 execve guuid=3a1758eb-1600-0000-f112-78f1e30d0000 pid=3555 /usr/bin/rm guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553->guuid=3a1758eb-1600-0000-f112-78f1e30d0000 pid=3555 execve guuid=4ce1adeb-1600-0000-f112-78f1e40d0000 pid=3556 /usr/bin/wget dns net send-data write-file guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553->guuid=4ce1adeb-1600-0000-f112-78f1e40d0000 pid=3556 execve guuid=9c686101-1700-0000-f112-78f1340e0000 pid=3636 /usr/bin/chmod guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553->guuid=9c686101-1700-0000-f112-78f1340e0000 pid=3636 execve guuid=ac6fa401-1700-0000-f112-78f1360e0000 pid=3638 /usr/bin/dash zombie guuid=8d1f42ea-1600-0000-f112-78f1e10d0000 pid=3553->guuid=ac6fa401-1700-0000-f112-78f1360e0000 pid=3638 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4ce1adeb-1600-0000-f112-78f1e40d0000 pid=3556->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B a392f2ec-b9d3-513d-9e67-bb306ba14eca wemqmewkqewq.work.gd:80 guuid=4ce1adeb-1600-0000-f112-78f1e40d0000 pid=3556->a392f2ec-b9d3-513d-9e67-bb306ba14eca send: 145B guuid=cff6e701-1700-0000-f112-78f1380e0000 pid=3640 /usr/bin/dash guuid=ac6fa401-1700-0000-f112-78f1360e0000 pid=3638->guuid=cff6e701-1700-0000-f112-78f1380e0000 pid=3640 clone guuid=587bf001-1700-0000-f112-78f1390e0000 pid=3641 /tmp/q zombie guuid=cff6e701-1700-0000-f112-78f1380e0000 pid=3640->guuid=587bf001-1700-0000-f112-78f1390e0000 pid=3641 execve guuid=907dd802-1700-0000-f112-78f13d0e0000 pid=3645 /tmp/q zombie guuid=587bf001-1700-0000-f112-78f1390e0000 pid=3641->guuid=907dd802-1700-0000-f112-78f13d0e0000 pid=3645 clone guuid=ab44f302-1700-0000-f112-78f13e0e0000 pid=3646 /tmp/q dns net send-data write-file zombie guuid=907dd802-1700-0000-f112-78f13d0e0000 pid=3645->guuid=ab44f302-1700-0000-f112-78f13e0e0000 pid=3646 clone guuid=ab44f302-1700-0000-f112-78f13e0e0000 pid=3646->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B 6655c9ec-8781-5932-bd74-1f48d7baa7dc emwqkekwqmekwq.work.gd:37215 guuid=ab44f302-1700-0000-f112-78f13e0e0000 pid=3646->6655c9ec-8781-5932-bd74-1f48d7baa7dc send: 5729075B guuid=bc5f0803-1700-0000-f112-78f13f0e0000 pid=3647 /tmp/q guuid=ab44f302-1700-0000-f112-78f13e0e0000 pid=3646->guuid=bc5f0803-1700-0000-f112-78f13f0e0000 pid=3647 clone guuid=928a0e03-1700-0000-f112-78f1400e0000 pid=3648 /tmp/q guuid=bc5f0803-1700-0000-f112-78f13f0e0000 pid=3647->guuid=928a0e03-1700-0000-f112-78f1400e0000 pid=3648 clone guuid=2d171903-1700-0000-f112-78f1410e0000 pid=3649 /tmp/q guuid=bc5f0803-1700-0000-f112-78f13f0e0000 pid=3647->guuid=2d171903-1700-0000-f112-78f1410e0000 pid=3649 clone
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SCRIPT_Dropper_Unknown_ForgeAuto_49674744
Author:Marjoriefort
Description:Detects Unknown (script_sh, etat binaire)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments