MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbd321f8ac5eb6a67cf1506b9447c8bf02a91da29558b1197fc023d02110da6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: cbd321f8ac5eb6a67cf1506b9447c8bf02a91da29558b1197fc023d02110da6d
SHA3-384 hash: 1dd7b6f6a516dee4e4be6d0ea6e29d7949de7fd561a6cbef7ff98aaa9cfb61f58c2ed73d3658195cb7a7e93da514bfec
SHA1 hash: a1355a16df759f563c48c8dac060cbfe1f520d3f
MD5 hash: 47bcbf2fe5a385bf3df9d8a726074a18
humanhash: cat-batman-kilo-skylark
File name:p
Download: download sample
File size:835 bytes
First seen:2026-06-20 09:05:18 UTC
Last seen:2026-06-20 17:11:06 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkaT80FC2QhCwyVx6CEzigC1xxCzUauD:kXCKysE2hi0ziQvZohaT88YRyOyguCU7
TLSH T1A801C6DA87509A104069DB1E629752A0B811D3CE0A8B0B747F9C5D3DFB88514B056F48
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/KBwn/an/aelf ua-wget
http://129.121.114.124/0x5gn/an/aelf ua-wget
http://129.121.114.124/7T8n/an/aelf ua-wget
http://129.121.114.124/L5tMn/an/aelf ua-wget
http://129.121.114.124/mA4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-20T06:15:00Z UTC
Last seen:
2026-06-20T08:47:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c208b36c-1900-0000-a92e-1ce42f140000 pid=5167 /usr/bin/sudo guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168 /tmp/sample.bin write-file guuid=c208b36c-1900-0000-a92e-1ce42f140000 pid=5167->guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168 execve guuid=4702d46e-1900-0000-a92e-1ce431140000 pid=5169 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4702d46e-1900-0000-a92e-1ce431140000 pid=5169 execve guuid=4cf7a66f-1900-0000-a92e-1ce432140000 pid=5170 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4cf7a66f-1900-0000-a92e-1ce432140000 pid=5170 execve guuid=f4a01670-1900-0000-a92e-1ce433140000 pid=5171 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f4a01670-1900-0000-a92e-1ce433140000 pid=5171 execve guuid=79428370-1900-0000-a92e-1ce434140000 pid=5172 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=79428370-1900-0000-a92e-1ce434140000 pid=5172 execve guuid=f6f9f770-1900-0000-a92e-1ce435140000 pid=5173 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f6f9f770-1900-0000-a92e-1ce435140000 pid=5173 execve guuid=4d12b871-1900-0000-a92e-1ce436140000 pid=5174 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4d12b871-1900-0000-a92e-1ce436140000 pid=5174 execve guuid=fd382e72-1900-0000-a92e-1ce437140000 pid=5175 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=fd382e72-1900-0000-a92e-1ce437140000 pid=5175 execve guuid=2deca272-1900-0000-a92e-1ce438140000 pid=5176 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=2deca272-1900-0000-a92e-1ce438140000 pid=5176 execve guuid=f1bd1973-1900-0000-a92e-1ce439140000 pid=5177 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f1bd1973-1900-0000-a92e-1ce439140000 pid=5177 execve guuid=d6078673-1900-0000-a92e-1ce43a140000 pid=5178 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d6078673-1900-0000-a92e-1ce43a140000 pid=5178 execve guuid=4dfaf273-1900-0000-a92e-1ce43b140000 pid=5179 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4dfaf273-1900-0000-a92e-1ce43b140000 pid=5179 execve guuid=331d6a74-1900-0000-a92e-1ce43c140000 pid=5180 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=331d6a74-1900-0000-a92e-1ce43c140000 pid=5180 execve guuid=3b15de74-1900-0000-a92e-1ce43d140000 pid=5181 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=3b15de74-1900-0000-a92e-1ce43d140000 pid=5181 execve guuid=fa915575-1900-0000-a92e-1ce43e140000 pid=5182 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=fa915575-1900-0000-a92e-1ce43e140000 pid=5182 execve guuid=b118cf75-1900-0000-a92e-1ce43f140000 pid=5183 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=b118cf75-1900-0000-a92e-1ce43f140000 pid=5183 execve guuid=6ea94476-1900-0000-a92e-1ce440140000 pid=5184 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=6ea94476-1900-0000-a92e-1ce440140000 pid=5184 execve guuid=2b07bc76-1900-0000-a92e-1ce441140000 pid=5185 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=2b07bc76-1900-0000-a92e-1ce441140000 pid=5185 execve guuid=d6832e77-1900-0000-a92e-1ce442140000 pid=5186 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d6832e77-1900-0000-a92e-1ce442140000 pid=5186 execve guuid=e2bda377-1900-0000-a92e-1ce443140000 pid=5187 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=e2bda377-1900-0000-a92e-1ce443140000 pid=5187 execve guuid=4c2a1b78-1900-0000-a92e-1ce444140000 pid=5188 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4c2a1b78-1900-0000-a92e-1ce444140000 pid=5188 execve guuid=f6e18b78-1900-0000-a92e-1ce445140000 pid=5189 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f6e18b78-1900-0000-a92e-1ce445140000 pid=5189 execve guuid=68dd1779-1900-0000-a92e-1ce446140000 pid=5190 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=68dd1779-1900-0000-a92e-1ce446140000 pid=5190 execve guuid=5e359179-1900-0000-a92e-1ce447140000 pid=5191 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=5e359179-1900-0000-a92e-1ce447140000 pid=5191 execve guuid=c2cb0a7a-1900-0000-a92e-1ce448140000 pid=5192 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=c2cb0a7a-1900-0000-a92e-1ce448140000 pid=5192 execve guuid=a52a7a7a-1900-0000-a92e-1ce449140000 pid=5193 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a52a7a7a-1900-0000-a92e-1ce449140000 pid=5193 execve guuid=0146ea7a-1900-0000-a92e-1ce44a140000 pid=5194 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=0146ea7a-1900-0000-a92e-1ce44a140000 pid=5194 execve guuid=354d597b-1900-0000-a92e-1ce44b140000 pid=5195 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=354d597b-1900-0000-a92e-1ce44b140000 pid=5195 execve guuid=c027cc7b-1900-0000-a92e-1ce44c140000 pid=5196 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=c027cc7b-1900-0000-a92e-1ce44c140000 pid=5196 execve guuid=f2c43d7c-1900-0000-a92e-1ce44d140000 pid=5197 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f2c43d7c-1900-0000-a92e-1ce44d140000 pid=5197 execve guuid=74dab17c-1900-0000-a92e-1ce44e140000 pid=5198 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=74dab17c-1900-0000-a92e-1ce44e140000 pid=5198 execve guuid=5ad3267d-1900-0000-a92e-1ce44f140000 pid=5199 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=5ad3267d-1900-0000-a92e-1ce44f140000 pid=5199 execve guuid=6b1c9d7d-1900-0000-a92e-1ce450140000 pid=5200 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=6b1c9d7d-1900-0000-a92e-1ce450140000 pid=5200 execve guuid=0a34107e-1900-0000-a92e-1ce451140000 pid=5201 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=0a34107e-1900-0000-a92e-1ce451140000 pid=5201 execve guuid=eb3b807e-1900-0000-a92e-1ce452140000 pid=5202 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=eb3b807e-1900-0000-a92e-1ce452140000 pid=5202 execve guuid=a4b7f77e-1900-0000-a92e-1ce453140000 pid=5203 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a4b7f77e-1900-0000-a92e-1ce453140000 pid=5203 execve guuid=07ef687f-1900-0000-a92e-1ce454140000 pid=5204 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=07ef687f-1900-0000-a92e-1ce454140000 pid=5204 execve guuid=8d07de7f-1900-0000-a92e-1ce455140000 pid=5205 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=8d07de7f-1900-0000-a92e-1ce455140000 pid=5205 execve guuid=4ba95780-1900-0000-a92e-1ce456140000 pid=5206 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4ba95780-1900-0000-a92e-1ce456140000 pid=5206 execve guuid=780ec880-1900-0000-a92e-1ce457140000 pid=5207 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=780ec880-1900-0000-a92e-1ce457140000 pid=5207 execve guuid=e0163d81-1900-0000-a92e-1ce458140000 pid=5208 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=e0163d81-1900-0000-a92e-1ce458140000 pid=5208 execve guuid=7121b081-1900-0000-a92e-1ce459140000 pid=5209 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=7121b081-1900-0000-a92e-1ce459140000 pid=5209 execve guuid=24fe2482-1900-0000-a92e-1ce45a140000 pid=5210 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=24fe2482-1900-0000-a92e-1ce45a140000 pid=5210 execve guuid=52209582-1900-0000-a92e-1ce45b140000 pid=5211 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=52209582-1900-0000-a92e-1ce45b140000 pid=5211 execve guuid=d62f6383-1900-0000-a92e-1ce45c140000 pid=5212 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d62f6383-1900-0000-a92e-1ce45c140000 pid=5212 execve guuid=6fe0cc83-1900-0000-a92e-1ce45d140000 pid=5213 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=6fe0cc83-1900-0000-a92e-1ce45d140000 pid=5213 execve guuid=d2e33f84-1900-0000-a92e-1ce45e140000 pid=5214 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d2e33f84-1900-0000-a92e-1ce45e140000 pid=5214 execve guuid=b085af84-1900-0000-a92e-1ce45f140000 pid=5215 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=b085af84-1900-0000-a92e-1ce45f140000 pid=5215 execve guuid=796f2585-1900-0000-a92e-1ce460140000 pid=5216 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=796f2585-1900-0000-a92e-1ce460140000 pid=5216 execve guuid=1c0ef385-1900-0000-a92e-1ce461140000 pid=5217 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=1c0ef385-1900-0000-a92e-1ce461140000 pid=5217 execve guuid=8d5f6386-1900-0000-a92e-1ce462140000 pid=5218 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=8d5f6386-1900-0000-a92e-1ce462140000 pid=5218 execve guuid=780bdb86-1900-0000-a92e-1ce463140000 pid=5219 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=780bdb86-1900-0000-a92e-1ce463140000 pid=5219 execve guuid=20895087-1900-0000-a92e-1ce464140000 pid=5220 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=20895087-1900-0000-a92e-1ce464140000 pid=5220 execve guuid=59fac187-1900-0000-a92e-1ce465140000 pid=5221 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=59fac187-1900-0000-a92e-1ce465140000 pid=5221 execve guuid=d3573588-1900-0000-a92e-1ce466140000 pid=5222 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d3573588-1900-0000-a92e-1ce466140000 pid=5222 execve guuid=3ad7a688-1900-0000-a92e-1ce467140000 pid=5223 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=3ad7a688-1900-0000-a92e-1ce467140000 pid=5223 execve guuid=12561a89-1900-0000-a92e-1ce468140000 pid=5224 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=12561a89-1900-0000-a92e-1ce468140000 pid=5224 execve guuid=eef98589-1900-0000-a92e-1ce469140000 pid=5225 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=eef98589-1900-0000-a92e-1ce469140000 pid=5225 execve guuid=1840ea89-1900-0000-a92e-1ce46a140000 pid=5226 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=1840ea89-1900-0000-a92e-1ce46a140000 pid=5226 execve guuid=0b074f8a-1900-0000-a92e-1ce46b140000 pid=5227 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=0b074f8a-1900-0000-a92e-1ce46b140000 pid=5227 execve guuid=5d85ba8a-1900-0000-a92e-1ce46c140000 pid=5228 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=5d85ba8a-1900-0000-a92e-1ce46c140000 pid=5228 execve guuid=b812328b-1900-0000-a92e-1ce46d140000 pid=5229 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=b812328b-1900-0000-a92e-1ce46d140000 pid=5229 execve guuid=4128a48b-1900-0000-a92e-1ce46e140000 pid=5230 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4128a48b-1900-0000-a92e-1ce46e140000 pid=5230 execve guuid=e81e0f8c-1900-0000-a92e-1ce46f140000 pid=5231 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=e81e0f8c-1900-0000-a92e-1ce46f140000 pid=5231 execve guuid=790b7f8c-1900-0000-a92e-1ce470140000 pid=5232 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=790b7f8c-1900-0000-a92e-1ce470140000 pid=5232 execve guuid=0b2ded8c-1900-0000-a92e-1ce471140000 pid=5233 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=0b2ded8c-1900-0000-a92e-1ce471140000 pid=5233 execve guuid=7f18628d-1900-0000-a92e-1ce472140000 pid=5234 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=7f18628d-1900-0000-a92e-1ce472140000 pid=5234 execve guuid=6bbed38d-1900-0000-a92e-1ce473140000 pid=5235 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=6bbed38d-1900-0000-a92e-1ce473140000 pid=5235 execve guuid=30a0408e-1900-0000-a92e-1ce474140000 pid=5236 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=30a0408e-1900-0000-a92e-1ce474140000 pid=5236 execve guuid=d222ae8e-1900-0000-a92e-1ce475140000 pid=5237 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d222ae8e-1900-0000-a92e-1ce475140000 pid=5237 execve guuid=9985218f-1900-0000-a92e-1ce476140000 pid=5238 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=9985218f-1900-0000-a92e-1ce476140000 pid=5238 execve guuid=0a77938f-1900-0000-a92e-1ce477140000 pid=5239 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=0a77938f-1900-0000-a92e-1ce477140000 pid=5239 execve guuid=7e660b90-1900-0000-a92e-1ce478140000 pid=5240 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=7e660b90-1900-0000-a92e-1ce478140000 pid=5240 execve guuid=52738790-1900-0000-a92e-1ce479140000 pid=5241 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=52738790-1900-0000-a92e-1ce479140000 pid=5241 execve guuid=fba5eb90-1900-0000-a92e-1ce47a140000 pid=5242 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=fba5eb90-1900-0000-a92e-1ce47a140000 pid=5242 execve guuid=60105891-1900-0000-a92e-1ce47b140000 pid=5243 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=60105891-1900-0000-a92e-1ce47b140000 pid=5243 execve guuid=e56ec391-1900-0000-a92e-1ce47c140000 pid=5244 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=e56ec391-1900-0000-a92e-1ce47c140000 pid=5244 execve guuid=0e3e3592-1900-0000-a92e-1ce47d140000 pid=5245 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=0e3e3592-1900-0000-a92e-1ce47d140000 pid=5245 execve guuid=8913a592-1900-0000-a92e-1ce47e140000 pid=5246 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=8913a592-1900-0000-a92e-1ce47e140000 pid=5246 execve guuid=3c2a1593-1900-0000-a92e-1ce47f140000 pid=5247 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=3c2a1593-1900-0000-a92e-1ce47f140000 pid=5247 execve guuid=89039093-1900-0000-a92e-1ce480140000 pid=5248 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=89039093-1900-0000-a92e-1ce480140000 pid=5248 execve guuid=91750494-1900-0000-a92e-1ce481140000 pid=5249 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=91750494-1900-0000-a92e-1ce481140000 pid=5249 execve guuid=b2ec7894-1900-0000-a92e-1ce482140000 pid=5250 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=b2ec7894-1900-0000-a92e-1ce482140000 pid=5250 execve guuid=e412ee94-1900-0000-a92e-1ce483140000 pid=5251 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=e412ee94-1900-0000-a92e-1ce483140000 pid=5251 execve guuid=3d7f6695-1900-0000-a92e-1ce484140000 pid=5252 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=3d7f6695-1900-0000-a92e-1ce484140000 pid=5252 execve guuid=12a9d395-1900-0000-a92e-1ce485140000 pid=5253 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=12a9d395-1900-0000-a92e-1ce485140000 pid=5253 execve guuid=a2d79f96-1900-0000-a92e-1ce486140000 pid=5254 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a2d79f96-1900-0000-a92e-1ce486140000 pid=5254 execve guuid=bd761097-1900-0000-a92e-1ce487140000 pid=5255 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=bd761097-1900-0000-a92e-1ce487140000 pid=5255 execve guuid=95177897-1900-0000-a92e-1ce488140000 pid=5256 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=95177897-1900-0000-a92e-1ce488140000 pid=5256 execve guuid=e6c3de97-1900-0000-a92e-1ce489140000 pid=5257 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=e6c3de97-1900-0000-a92e-1ce489140000 pid=5257 execve guuid=fc154598-1900-0000-a92e-1ce48a140000 pid=5258 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=fc154598-1900-0000-a92e-1ce48a140000 pid=5258 execve guuid=f4e9af98-1900-0000-a92e-1ce48b140000 pid=5259 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f4e9af98-1900-0000-a92e-1ce48b140000 pid=5259 execve guuid=1c381899-1900-0000-a92e-1ce48c140000 pid=5260 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=1c381899-1900-0000-a92e-1ce48c140000 pid=5260 execve guuid=fb588599-1900-0000-a92e-1ce48d140000 pid=5261 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=fb588599-1900-0000-a92e-1ce48d140000 pid=5261 execve guuid=cfa8f799-1900-0000-a92e-1ce48e140000 pid=5262 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=cfa8f799-1900-0000-a92e-1ce48e140000 pid=5262 execve guuid=bbc86b9a-1900-0000-a92e-1ce48f140000 pid=5263 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=bbc86b9a-1900-0000-a92e-1ce48f140000 pid=5263 execve guuid=d439dd9a-1900-0000-a92e-1ce490140000 pid=5264 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d439dd9a-1900-0000-a92e-1ce490140000 pid=5264 execve guuid=a38e559b-1900-0000-a92e-1ce491140000 pid=5265 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a38e559b-1900-0000-a92e-1ce491140000 pid=5265 execve guuid=8feace9b-1900-0000-a92e-1ce492140000 pid=5266 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=8feace9b-1900-0000-a92e-1ce492140000 pid=5266 execve guuid=cf58419c-1900-0000-a92e-1ce493140000 pid=5267 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=cf58419c-1900-0000-a92e-1ce493140000 pid=5267 execve guuid=978db39c-1900-0000-a92e-1ce494140000 pid=5268 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=978db39c-1900-0000-a92e-1ce494140000 pid=5268 execve guuid=a83f2e9d-1900-0000-a92e-1ce495140000 pid=5269 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a83f2e9d-1900-0000-a92e-1ce495140000 pid=5269 execve guuid=cb109f9d-1900-0000-a92e-1ce496140000 pid=5270 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=cb109f9d-1900-0000-a92e-1ce496140000 pid=5270 execve guuid=38dc149e-1900-0000-a92e-1ce497140000 pid=5271 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=38dc149e-1900-0000-a92e-1ce497140000 pid=5271 execve guuid=48b9839e-1900-0000-a92e-1ce498140000 pid=5272 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=48b9839e-1900-0000-a92e-1ce498140000 pid=5272 execve guuid=ca21f29e-1900-0000-a92e-1ce499140000 pid=5273 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=ca21f29e-1900-0000-a92e-1ce499140000 pid=5273 execve guuid=5097a6a0-1900-0000-a92e-1ce49a140000 pid=5274 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=5097a6a0-1900-0000-a92e-1ce49a140000 pid=5274 execve guuid=56261da1-1900-0000-a92e-1ce49b140000 pid=5275 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=56261da1-1900-0000-a92e-1ce49b140000 pid=5275 execve guuid=da588ca1-1900-0000-a92e-1ce49c140000 pid=5276 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=da588ca1-1900-0000-a92e-1ce49c140000 pid=5276 execve guuid=c326fea1-1900-0000-a92e-1ce49d140000 pid=5277 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=c326fea1-1900-0000-a92e-1ce49d140000 pid=5277 execve guuid=26246fa2-1900-0000-a92e-1ce49e140000 pid=5278 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=26246fa2-1900-0000-a92e-1ce49e140000 pid=5278 execve guuid=3e3cdaa2-1900-0000-a92e-1ce49f140000 pid=5279 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=3e3cdaa2-1900-0000-a92e-1ce49f140000 pid=5279 execve guuid=9aa74aa3-1900-0000-a92e-1ce4a0140000 pid=5280 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=9aa74aa3-1900-0000-a92e-1ce4a0140000 pid=5280 execve guuid=1a6ebba3-1900-0000-a92e-1ce4a1140000 pid=5281 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=1a6ebba3-1900-0000-a92e-1ce4a1140000 pid=5281 execve guuid=df9e21a4-1900-0000-a92e-1ce4a2140000 pid=5282 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=df9e21a4-1900-0000-a92e-1ce4a2140000 pid=5282 execve guuid=6d748ba4-1900-0000-a92e-1ce4a3140000 pid=5283 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=6d748ba4-1900-0000-a92e-1ce4a3140000 pid=5283 execve guuid=b7a2f5a4-1900-0000-a92e-1ce4a4140000 pid=5284 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=b7a2f5a4-1900-0000-a92e-1ce4a4140000 pid=5284 execve guuid=a12a65a5-1900-0000-a92e-1ce4a5140000 pid=5285 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a12a65a5-1900-0000-a92e-1ce4a5140000 pid=5285 execve guuid=4d21cfa5-1900-0000-a92e-1ce4a6140000 pid=5286 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=4d21cfa5-1900-0000-a92e-1ce4a6140000 pid=5286 execve guuid=768234a6-1900-0000-a92e-1ce4a7140000 pid=5287 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=768234a6-1900-0000-a92e-1ce4a7140000 pid=5287 execve guuid=db63a0a6-1900-0000-a92e-1ce4a8140000 pid=5288 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=db63a0a6-1900-0000-a92e-1ce4a8140000 pid=5288 execve guuid=79fc0ba7-1900-0000-a92e-1ce4a9140000 pid=5289 /usr/bin/ls guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=79fc0ba7-1900-0000-a92e-1ce4a9140000 pid=5289 execve guuid=b32174a7-1900-0000-a92e-1ce4aa140000 pid=5290 /usr/bin/rm guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=b32174a7-1900-0000-a92e-1ce4aa140000 pid=5290 execve guuid=3799baa7-1900-0000-a92e-1ce4ab140000 pid=5291 /usr/bin/wget net send-data write-file guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=3799baa7-1900-0000-a92e-1ce4ab140000 pid=5291 execve guuid=919a17c2-1900-0000-a92e-1ce4ac140000 pid=5292 /usr/bin/chmod guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=919a17c2-1900-0000-a92e-1ce4ac140000 pid=5292 execve guuid=9c9f62c2-1900-0000-a92e-1ce4ad140000 pid=5293 /usr/bin/dash guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=9c9f62c2-1900-0000-a92e-1ce4ad140000 pid=5293 clone guuid=f26bfec2-1900-0000-a92e-1ce4af140000 pid=5295 /usr/bin/rm guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=f26bfec2-1900-0000-a92e-1ce4af140000 pid=5295 execve guuid=eb8441c3-1900-0000-a92e-1ce4b0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=eb8441c3-1900-0000-a92e-1ce4b0140000 pid=5296 execve guuid=d25b97db-1900-0000-a92e-1ce4b1140000 pid=5297 /usr/bin/chmod guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d25b97db-1900-0000-a92e-1ce4b1140000 pid=5297 execve guuid=625413dc-1900-0000-a92e-1ce4b2140000 pid=5298 /usr/bin/dash guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=625413dc-1900-0000-a92e-1ce4b2140000 pid=5298 clone guuid=9e52dfde-1900-0000-a92e-1ce4b4140000 pid=5300 /usr/bin/rm guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=9e52dfde-1900-0000-a92e-1ce4b4140000 pid=5300 execve guuid=241431df-1900-0000-a92e-1ce4b5140000 pid=5301 /usr/bin/wget net send-data write-file guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=241431df-1900-0000-a92e-1ce4b5140000 pid=5301 execve guuid=c72692f8-1900-0000-a92e-1ce4b6140000 pid=5302 /usr/bin/chmod guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=c72692f8-1900-0000-a92e-1ce4b6140000 pid=5302 execve guuid=2764d7f8-1900-0000-a92e-1ce4b7140000 pid=5303 /usr/bin/dash guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=2764d7f8-1900-0000-a92e-1ce4b7140000 pid=5303 clone guuid=d04b68f9-1900-0000-a92e-1ce4b9140000 pid=5305 /usr/bin/rm guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d04b68f9-1900-0000-a92e-1ce4b9140000 pid=5305 execve guuid=a98fb7f9-1900-0000-a92e-1ce4ba140000 pid=5306 /usr/bin/wget net send-data write-file guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a98fb7f9-1900-0000-a92e-1ce4ba140000 pid=5306 execve guuid=a700ba17-1a00-0000-a92e-1ce4bb140000 pid=5307 /usr/bin/chmod guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=a700ba17-1a00-0000-a92e-1ce4bb140000 pid=5307 execve guuid=ec6c1a18-1a00-0000-a92e-1ce4bc140000 pid=5308 /usr/bin/dash guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=ec6c1a18-1a00-0000-a92e-1ce4bc140000 pid=5308 clone guuid=d97d0919-1a00-0000-a92e-1ce4be140000 pid=5310 /usr/bin/rm guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=d97d0919-1a00-0000-a92e-1ce4be140000 pid=5310 execve guuid=11245619-1a00-0000-a92e-1ce4bf140000 pid=5311 /usr/bin/wget net send-data write-file guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=11245619-1a00-0000-a92e-1ce4bf140000 pid=5311 execve guuid=994d0f39-1a00-0000-a92e-1ce4c7140000 pid=5319 /usr/bin/chmod guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=994d0f39-1a00-0000-a92e-1ce4c7140000 pid=5319 execve guuid=877df139-1a00-0000-a92e-1ce4c8140000 pid=5320 /usr/bin/dash guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=877df139-1a00-0000-a92e-1ce4c8140000 pid=5320 clone guuid=df88a13b-1a00-0000-a92e-1ce4ca140000 pid=5322 /usr/bin/rm delete-file guuid=3dc18d6e-1900-0000-a92e-1ce430140000 pid=5168->guuid=df88a13b-1a00-0000-a92e-1ce4ca140000 pid=5322 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=3799baa7-1900-0000-a92e-1ce4ab140000 pid=5291->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=eb8441c3-1900-0000-a92e-1ce4b0140000 pid=5296->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=241431df-1900-0000-a92e-1ce4b5140000 pid=5301->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=a98fb7f9-1900-0000-a92e-1ce4ba140000 pid=5306->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=11245619-1a00-0000-a92e-1ce4bf140000 pid=5311->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Threat name:
Document-HTML.Downloader.Bash
Status:
Malicious
First seen:
2026-06-20 09:05:56 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh cbd321f8ac5eb6a67cf1506b9447c8bf02a91da29558b1197fc023d02110da6d

(this sample)

  
Delivery method
Distributed via web download

Comments