MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dfcc7e51de3679d12f6d16464cd4e1d73734957f67fce02abe8d8ce1ff332b87. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: dfcc7e51de3679d12f6d16464cd4e1d73734957f67fce02abe8d8ce1ff332b87
SHA3-384 hash: 443a619e8579c579f0ca87b09e5201ebb3f4aa4248ae2d74d6f36ff70fd6c504e1dca9e918ddc7868762f56ba3b91a81
SHA1 hash: 399b7886486f6c14baa4f5d5c42a43f6801ace9e
MD5 hash: 3f23e6b16120e717d485d3f4932cb495
humanhash: london-romeo-red-emma
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-10 01:02:11 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaeymVSNo4N+FztkDL7:e9Qp+Mseymj4szGL7
TLSH T14801CEDAC113CB604189E89E63DB21807421C3CB66464FFC7F9C443EBBAC6587026F88
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/EJ9Gn/an/aelf ua-wget
http://188.132.232.81/677Nn/an/aelf ua-wget
http://188.132.232.81/r2Wn/an/aelf ua-wget
http://188.132.232.81/M2j9n/an/aelf ua-wget
http://188.132.232.81/VAZn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=a32e42ff-1600-0000-fe5d-d5d5910d0000 pid=3473 /usr/bin/sudo guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480 /tmp/sample.bin write-file guuid=a32e42ff-1600-0000-fe5d-d5d5910d0000 pid=3473->guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480 execve guuid=1559cc02-1700-0000-fe5d-d5d5990d0000 pid=3481 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=1559cc02-1700-0000-fe5d-d5d5990d0000 pid=3481 execve guuid=21ad0404-1700-0000-fe5d-d5d5a00d0000 pid=3488 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=21ad0404-1700-0000-fe5d-d5d5a00d0000 pid=3488 execve guuid=86567104-1700-0000-fe5d-d5d5a10d0000 pid=3489 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=86567104-1700-0000-fe5d-d5d5a10d0000 pid=3489 execve guuid=491a5605-1700-0000-fe5d-d5d5a20d0000 pid=3490 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=491a5605-1700-0000-fe5d-d5d5a20d0000 pid=3490 execve guuid=a74c1f06-1700-0000-fe5d-d5d5a30d0000 pid=3491 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=a74c1f06-1700-0000-fe5d-d5d5a30d0000 pid=3491 execve guuid=29bbae06-1700-0000-fe5d-d5d5a40d0000 pid=3492 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=29bbae06-1700-0000-fe5d-d5d5a40d0000 pid=3492 execve guuid=f8263a07-1700-0000-fe5d-d5d5a50d0000 pid=3493 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f8263a07-1700-0000-fe5d-d5d5a50d0000 pid=3493 execve guuid=c9befb07-1700-0000-fe5d-d5d5a60d0000 pid=3494 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=c9befb07-1700-0000-fe5d-d5d5a60d0000 pid=3494 execve guuid=a6427e08-1700-0000-fe5d-d5d5a70d0000 pid=3495 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=a6427e08-1700-0000-fe5d-d5d5a70d0000 pid=3495 execve guuid=c9e1fc08-1700-0000-fe5d-d5d5a80d0000 pid=3496 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=c9e1fc08-1700-0000-fe5d-d5d5a80d0000 pid=3496 execve guuid=27a08009-1700-0000-fe5d-d5d5a90d0000 pid=3497 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=27a08009-1700-0000-fe5d-d5d5a90d0000 pid=3497 execve guuid=f600fd09-1700-0000-fe5d-d5d5aa0d0000 pid=3498 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f600fd09-1700-0000-fe5d-d5d5aa0d0000 pid=3498 execve guuid=aa75780a-1700-0000-fe5d-d5d5ab0d0000 pid=3499 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=aa75780a-1700-0000-fe5d-d5d5ab0d0000 pid=3499 execve guuid=11e3fd0a-1700-0000-fe5d-d5d5ac0d0000 pid=3500 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=11e3fd0a-1700-0000-fe5d-d5d5ac0d0000 pid=3500 execve guuid=e14c7e0b-1700-0000-fe5d-d5d5b00d0000 pid=3504 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=e14c7e0b-1700-0000-fe5d-d5d5b00d0000 pid=3504 execve guuid=1136f00b-1700-0000-fe5d-d5d5b10d0000 pid=3505 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=1136f00b-1700-0000-fe5d-d5d5b10d0000 pid=3505 execve guuid=b24db30c-1700-0000-fe5d-d5d5b40d0000 pid=3508 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=b24db30c-1700-0000-fe5d-d5d5b40d0000 pid=3508 execve guuid=ebab2f0d-1700-0000-fe5d-d5d5b60d0000 pid=3510 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ebab2f0d-1700-0000-fe5d-d5d5b60d0000 pid=3510 execve guuid=04a8a40d-1700-0000-fe5d-d5d5b80d0000 pid=3512 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=04a8a40d-1700-0000-fe5d-d5d5b80d0000 pid=3512 execve guuid=20e81a0e-1700-0000-fe5d-d5d5bb0d0000 pid=3515 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=20e81a0e-1700-0000-fe5d-d5d5bb0d0000 pid=3515 execve guuid=80ac960e-1700-0000-fe5d-d5d5bd0d0000 pid=3517 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=80ac960e-1700-0000-fe5d-d5d5bd0d0000 pid=3517 execve guuid=6753210f-1700-0000-fe5d-d5d5bf0d0000 pid=3519 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=6753210f-1700-0000-fe5d-d5d5bf0d0000 pid=3519 execve guuid=3905ad0f-1700-0000-fe5d-d5d5c20d0000 pid=3522 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=3905ad0f-1700-0000-fe5d-d5d5c20d0000 pid=3522 execve guuid=c80c4110-1700-0000-fe5d-d5d5c30d0000 pid=3523 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=c80c4110-1700-0000-fe5d-d5d5c30d0000 pid=3523 execve guuid=56b3c510-1700-0000-fe5d-d5d5c50d0000 pid=3525 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=56b3c510-1700-0000-fe5d-d5d5c50d0000 pid=3525 execve guuid=b66b5011-1700-0000-fe5d-d5d5c70d0000 pid=3527 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=b66b5011-1700-0000-fe5d-d5d5c70d0000 pid=3527 execve guuid=1a5acf11-1700-0000-fe5d-d5d5c90d0000 pid=3529 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=1a5acf11-1700-0000-fe5d-d5d5c90d0000 pid=3529 execve guuid=09f34e12-1700-0000-fe5d-d5d5cb0d0000 pid=3531 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=09f34e12-1700-0000-fe5d-d5d5cb0d0000 pid=3531 execve guuid=684fda12-1700-0000-fe5d-d5d5ce0d0000 pid=3534 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=684fda12-1700-0000-fe5d-d5d5ce0d0000 pid=3534 execve guuid=18a95f13-1700-0000-fe5d-d5d5d00d0000 pid=3536 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=18a95f13-1700-0000-fe5d-d5d5d00d0000 pid=3536 execve guuid=c622e613-1700-0000-fe5d-d5d5d10d0000 pid=3537 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=c622e613-1700-0000-fe5d-d5d5d10d0000 pid=3537 execve guuid=30876014-1700-0000-fe5d-d5d5d30d0000 pid=3539 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=30876014-1700-0000-fe5d-d5d5d30d0000 pid=3539 execve guuid=7f7dd014-1700-0000-fe5d-d5d5d50d0000 pid=3541 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=7f7dd014-1700-0000-fe5d-d5d5d50d0000 pid=3541 execve guuid=190d4615-1700-0000-fe5d-d5d5d70d0000 pid=3543 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=190d4615-1700-0000-fe5d-d5d5d70d0000 pid=3543 execve guuid=125ebc15-1700-0000-fe5d-d5d5d90d0000 pid=3545 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=125ebc15-1700-0000-fe5d-d5d5d90d0000 pid=3545 execve guuid=1a692d16-1700-0000-fe5d-d5d5dc0d0000 pid=3548 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=1a692d16-1700-0000-fe5d-d5d5dc0d0000 pid=3548 execve guuid=2f75a116-1700-0000-fe5d-d5d5de0d0000 pid=3550 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=2f75a116-1700-0000-fe5d-d5d5de0d0000 pid=3550 execve guuid=54bc1617-1700-0000-fe5d-d5d5e00d0000 pid=3552 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=54bc1617-1700-0000-fe5d-d5d5e00d0000 pid=3552 execve guuid=f7518c17-1700-0000-fe5d-d5d5e20d0000 pid=3554 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f7518c17-1700-0000-fe5d-d5d5e20d0000 pid=3554 execve guuid=1e3f0518-1700-0000-fe5d-d5d5e50d0000 pid=3557 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=1e3f0518-1700-0000-fe5d-d5d5e50d0000 pid=3557 execve guuid=b7f97f18-1700-0000-fe5d-d5d5e70d0000 pid=3559 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=b7f97f18-1700-0000-fe5d-d5d5e70d0000 pid=3559 execve guuid=6a93f818-1700-0000-fe5d-d5d5e90d0000 pid=3561 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=6a93f818-1700-0000-fe5d-d5d5e90d0000 pid=3561 execve guuid=4a067b19-1700-0000-fe5d-d5d5ec0d0000 pid=3564 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=4a067b19-1700-0000-fe5d-d5d5ec0d0000 pid=3564 execve guuid=2a4df919-1700-0000-fe5d-d5d5ee0d0000 pid=3566 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=2a4df919-1700-0000-fe5d-d5d5ee0d0000 pid=3566 execve guuid=03c5591a-1700-0000-fe5d-d5d5f00d0000 pid=3568 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=03c5591a-1700-0000-fe5d-d5d5f00d0000 pid=3568 execve guuid=e471b31a-1700-0000-fe5d-d5d5f10d0000 pid=3569 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=e471b31a-1700-0000-fe5d-d5d5f10d0000 pid=3569 execve guuid=466f1e1b-1700-0000-fe5d-d5d5f30d0000 pid=3571 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=466f1e1b-1700-0000-fe5d-d5d5f30d0000 pid=3571 execve guuid=c5c1861b-1700-0000-fe5d-d5d5f50d0000 pid=3573 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=c5c1861b-1700-0000-fe5d-d5d5f50d0000 pid=3573 execve guuid=12a2e91b-1700-0000-fe5d-d5d5f70d0000 pid=3575 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=12a2e91b-1700-0000-fe5d-d5d5f70d0000 pid=3575 execve guuid=172b441c-1700-0000-fe5d-d5d5fa0d0000 pid=3578 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=172b441c-1700-0000-fe5d-d5d5fa0d0000 pid=3578 execve guuid=907ca61c-1700-0000-fe5d-d5d5fc0d0000 pid=3580 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=907ca61c-1700-0000-fe5d-d5d5fc0d0000 pid=3580 execve guuid=123c011d-1700-0000-fe5d-d5d5fe0d0000 pid=3582 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=123c011d-1700-0000-fe5d-d5d5fe0d0000 pid=3582 execve guuid=9ea66e1d-1700-0000-fe5d-d5d5010e0000 pid=3585 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=9ea66e1d-1700-0000-fe5d-d5d5010e0000 pid=3585 execve guuid=ca05bc1d-1700-0000-fe5d-d5d5030e0000 pid=3587 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ca05bc1d-1700-0000-fe5d-d5d5030e0000 pid=3587 execve guuid=f8ba201e-1700-0000-fe5d-d5d5060e0000 pid=3590 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f8ba201e-1700-0000-fe5d-d5d5060e0000 pid=3590 execve guuid=b47f871e-1700-0000-fe5d-d5d5080e0000 pid=3592 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=b47f871e-1700-0000-fe5d-d5d5080e0000 pid=3592 execve guuid=d5bad91e-1700-0000-fe5d-d5d50b0e0000 pid=3595 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=d5bad91e-1700-0000-fe5d-d5d50b0e0000 pid=3595 execve guuid=ece62d1f-1700-0000-fe5d-d5d50d0e0000 pid=3597 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ece62d1f-1700-0000-fe5d-d5d50d0e0000 pid=3597 execve guuid=e049821f-1700-0000-fe5d-d5d50f0e0000 pid=3599 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=e049821f-1700-0000-fe5d-d5d50f0e0000 pid=3599 execve guuid=cd71d41f-1700-0000-fe5d-d5d5120e0000 pid=3602 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=cd71d41f-1700-0000-fe5d-d5d5120e0000 pid=3602 execve guuid=f9a02720-1700-0000-fe5d-d5d5140e0000 pid=3604 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f9a02720-1700-0000-fe5d-d5d5140e0000 pid=3604 execve guuid=f0b97e20-1700-0000-fe5d-d5d5160e0000 pid=3606 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f0b97e20-1700-0000-fe5d-d5d5160e0000 pid=3606 execve guuid=f4fbcf20-1700-0000-fe5d-d5d5190e0000 pid=3609 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f4fbcf20-1700-0000-fe5d-d5d5190e0000 pid=3609 execve guuid=c4bd2721-1700-0000-fe5d-d5d51b0e0000 pid=3611 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=c4bd2721-1700-0000-fe5d-d5d51b0e0000 pid=3611 execve guuid=3d197f21-1700-0000-fe5d-d5d51d0e0000 pid=3613 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=3d197f21-1700-0000-fe5d-d5d51d0e0000 pid=3613 execve guuid=b578d421-1700-0000-fe5d-d5d5200e0000 pid=3616 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=b578d421-1700-0000-fe5d-d5d5200e0000 pid=3616 execve guuid=d2dc3522-1700-0000-fe5d-d5d5220e0000 pid=3618 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=d2dc3522-1700-0000-fe5d-d5d5220e0000 pid=3618 execve guuid=527c9a22-1700-0000-fe5d-d5d5240e0000 pid=3620 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=527c9a22-1700-0000-fe5d-d5d5240e0000 pid=3620 execve guuid=94363123-1700-0000-fe5d-d5d52a0e0000 pid=3626 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=94363123-1700-0000-fe5d-d5d52a0e0000 pid=3626 execve guuid=15529823-1700-0000-fe5d-d5d52c0e0000 pid=3628 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=15529823-1700-0000-fe5d-d5d52c0e0000 pid=3628 execve guuid=67b1f723-1700-0000-fe5d-d5d52d0e0000 pid=3629 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=67b1f723-1700-0000-fe5d-d5d52d0e0000 pid=3629 execve guuid=8a385724-1700-0000-fe5d-d5d52f0e0000 pid=3631 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=8a385724-1700-0000-fe5d-d5d52f0e0000 pid=3631 execve guuid=43a5ae24-1700-0000-fe5d-d5d5310e0000 pid=3633 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=43a5ae24-1700-0000-fe5d-d5d5310e0000 pid=3633 execve guuid=cee70425-1700-0000-fe5d-d5d5330e0000 pid=3635 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=cee70425-1700-0000-fe5d-d5d5330e0000 pid=3635 execve guuid=dff25725-1700-0000-fe5d-d5d5360e0000 pid=3638 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=dff25725-1700-0000-fe5d-d5d5360e0000 pid=3638 execve guuid=ee82af25-1700-0000-fe5d-d5d5370e0000 pid=3639 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ee82af25-1700-0000-fe5d-d5d5370e0000 pid=3639 execve guuid=60f60326-1700-0000-fe5d-d5d5390e0000 pid=3641 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=60f60326-1700-0000-fe5d-d5d5390e0000 pid=3641 execve guuid=e5725726-1700-0000-fe5d-d5d53c0e0000 pid=3644 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=e5725726-1700-0000-fe5d-d5d53c0e0000 pid=3644 execve guuid=67e3bb26-1700-0000-fe5d-d5d53e0e0000 pid=3646 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=67e3bb26-1700-0000-fe5d-d5d53e0e0000 pid=3646 execve guuid=6d041127-1700-0000-fe5d-d5d5400e0000 pid=3648 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=6d041127-1700-0000-fe5d-d5d5400e0000 pid=3648 execve guuid=8e816227-1700-0000-fe5d-d5d5420e0000 pid=3650 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=8e816227-1700-0000-fe5d-d5d5420e0000 pid=3650 execve guuid=0943ba27-1700-0000-fe5d-d5d5440e0000 pid=3652 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=0943ba27-1700-0000-fe5d-d5d5440e0000 pid=3652 execve guuid=dce41428-1700-0000-fe5d-d5d5460e0000 pid=3654 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=dce41428-1700-0000-fe5d-d5d5460e0000 pid=3654 execve guuid=7b766c28-1700-0000-fe5d-d5d5480e0000 pid=3656 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=7b766c28-1700-0000-fe5d-d5d5480e0000 pid=3656 execve guuid=47efc828-1700-0000-fe5d-d5d54a0e0000 pid=3658 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=47efc828-1700-0000-fe5d-d5d54a0e0000 pid=3658 execve guuid=048f2029-1700-0000-fe5d-d5d54d0e0000 pid=3661 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=048f2029-1700-0000-fe5d-d5d54d0e0000 pid=3661 execve guuid=0fc98929-1700-0000-fe5d-d5d54f0e0000 pid=3663 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=0fc98929-1700-0000-fe5d-d5d54f0e0000 pid=3663 execve guuid=3d56ef29-1700-0000-fe5d-d5d5510e0000 pid=3665 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=3d56ef29-1700-0000-fe5d-d5d5510e0000 pid=3665 execve guuid=f0b65e2a-1700-0000-fe5d-d5d5540e0000 pid=3668 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f0b65e2a-1700-0000-fe5d-d5d5540e0000 pid=3668 execve guuid=9042c72a-1700-0000-fe5d-d5d5560e0000 pid=3670 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=9042c72a-1700-0000-fe5d-d5d5560e0000 pid=3670 execve guuid=2695342b-1700-0000-fe5d-d5d5590e0000 pid=3673 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=2695342b-1700-0000-fe5d-d5d5590e0000 pid=3673 execve guuid=ed80cd2b-1700-0000-fe5d-d5d55c0e0000 pid=3676 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ed80cd2b-1700-0000-fe5d-d5d55c0e0000 pid=3676 execve guuid=6eb6972c-1700-0000-fe5d-d5d5600e0000 pid=3680 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=6eb6972c-1700-0000-fe5d-d5d5600e0000 pid=3680 execve guuid=808c6f2d-1700-0000-fe5d-d5d5610e0000 pid=3681 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=808c6f2d-1700-0000-fe5d-d5d5610e0000 pid=3681 execve guuid=d0f5222e-1700-0000-fe5d-d5d5640e0000 pid=3684 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=d0f5222e-1700-0000-fe5d-d5d5640e0000 pid=3684 execve guuid=833ad22e-1700-0000-fe5d-d5d5660e0000 pid=3686 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=833ad22e-1700-0000-fe5d-d5d5660e0000 pid=3686 execve guuid=a79b712f-1700-0000-fe5d-d5d5680e0000 pid=3688 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=a79b712f-1700-0000-fe5d-d5d5680e0000 pid=3688 execve guuid=894ec12f-1700-0000-fe5d-d5d56a0e0000 pid=3690 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=894ec12f-1700-0000-fe5d-d5d56a0e0000 pid=3690 execve guuid=603e4f30-1700-0000-fe5d-d5d56c0e0000 pid=3692 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=603e4f30-1700-0000-fe5d-d5d56c0e0000 pid=3692 execve guuid=0056d330-1700-0000-fe5d-d5d56f0e0000 pid=3695 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=0056d330-1700-0000-fe5d-d5d56f0e0000 pid=3695 execve guuid=31723731-1700-0000-fe5d-d5d5710e0000 pid=3697 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=31723731-1700-0000-fe5d-d5d5710e0000 pid=3697 execve guuid=bcbdb631-1700-0000-fe5d-d5d5730e0000 pid=3699 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=bcbdb631-1700-0000-fe5d-d5d5730e0000 pid=3699 execve guuid=ca133832-1700-0000-fe5d-d5d5740e0000 pid=3700 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ca133832-1700-0000-fe5d-d5d5740e0000 pid=3700 execve guuid=a97ac232-1700-0000-fe5d-d5d5750e0000 pid=3701 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=a97ac232-1700-0000-fe5d-d5d5750e0000 pid=3701 execve guuid=a37d4833-1700-0000-fe5d-d5d5770e0000 pid=3703 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=a37d4833-1700-0000-fe5d-d5d5770e0000 pid=3703 execve guuid=0815bf33-1700-0000-fe5d-d5d57a0e0000 pid=3706 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=0815bf33-1700-0000-fe5d-d5d57a0e0000 pid=3706 execve guuid=e40e2934-1700-0000-fe5d-d5d57c0e0000 pid=3708 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=e40e2934-1700-0000-fe5d-d5d57c0e0000 pid=3708 execve guuid=afeba334-1700-0000-fe5d-d5d57f0e0000 pid=3711 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=afeba334-1700-0000-fe5d-d5d57f0e0000 pid=3711 execve guuid=9e321b35-1700-0000-fe5d-d5d5820e0000 pid=3714 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=9e321b35-1700-0000-fe5d-d5d5820e0000 pid=3714 execve guuid=84cf9035-1700-0000-fe5d-d5d5840e0000 pid=3716 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=84cf9035-1700-0000-fe5d-d5d5840e0000 pid=3716 execve guuid=f9ff0b36-1700-0000-fe5d-d5d5870e0000 pid=3719 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f9ff0b36-1700-0000-fe5d-d5d5870e0000 pid=3719 execve guuid=11798836-1700-0000-fe5d-d5d58b0e0000 pid=3723 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=11798836-1700-0000-fe5d-d5d58b0e0000 pid=3723 execve guuid=7cae0637-1700-0000-fe5d-d5d58c0e0000 pid=3724 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=7cae0637-1700-0000-fe5d-d5d58c0e0000 pid=3724 execve guuid=41a87a37-1700-0000-fe5d-d5d5900e0000 pid=3728 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=41a87a37-1700-0000-fe5d-d5d5900e0000 pid=3728 execve guuid=bba40738-1700-0000-fe5d-d5d5940e0000 pid=3732 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=bba40738-1700-0000-fe5d-d5d5940e0000 pid=3732 execve guuid=30897d38-1700-0000-fe5d-d5d5980e0000 pid=3736 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=30897d38-1700-0000-fe5d-d5d5980e0000 pid=3736 execve guuid=2c66ef38-1700-0000-fe5d-d5d59c0e0000 pid=3740 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=2c66ef38-1700-0000-fe5d-d5d59c0e0000 pid=3740 execve guuid=44276239-1700-0000-fe5d-d5d59e0e0000 pid=3742 /usr/bin/ls guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=44276239-1700-0000-fe5d-d5d59e0e0000 pid=3742 execve guuid=2e20c939-1700-0000-fe5d-d5d5a00e0000 pid=3744 /usr/bin/rm guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=2e20c939-1700-0000-fe5d-d5d5a00e0000 pid=3744 execve guuid=0934063a-1700-0000-fe5d-d5d5a20e0000 pid=3746 /usr/bin/wget net send-data write-file guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=0934063a-1700-0000-fe5d-d5d5a20e0000 pid=3746 execve guuid=4136744f-1700-0000-fe5d-d5d5da0e0000 pid=3802 /usr/bin/chmod guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=4136744f-1700-0000-fe5d-d5d5da0e0000 pid=3802 execve guuid=baa9ec5f-1700-0000-fe5d-d5d5db0e0000 pid=3803 /tmp/EJ9G guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=baa9ec5f-1700-0000-fe5d-d5d5db0e0000 pid=3803 execve guuid=d3175861-1700-0000-fe5d-d5d5df0e0000 pid=3807 /usr/bin/rm guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=d3175861-1700-0000-fe5d-d5d5df0e0000 pid=3807 execve guuid=dec9c861-1700-0000-fe5d-d5d5e10e0000 pid=3809 /usr/bin/wget net send-data write-file guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=dec9c861-1700-0000-fe5d-d5d5e10e0000 pid=3809 execve guuid=433551e3-1700-0000-fe5d-d5d57f100000 pid=4223 /usr/bin/chmod guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=433551e3-1700-0000-fe5d-d5d57f100000 pid=4223 execve guuid=f083c6e3-1700-0000-fe5d-d5d581100000 pid=4225 /tmp/677N guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=f083c6e3-1700-0000-fe5d-d5d581100000 pid=4225 execve guuid=08def4e4-1700-0000-fe5d-d5d586100000 pid=4230 /usr/bin/rm guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=08def4e4-1700-0000-fe5d-d5d586100000 pid=4230 execve guuid=fa9449e5-1700-0000-fe5d-d5d587100000 pid=4231 /usr/bin/wget net send-data write-file guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=fa9449e5-1700-0000-fe5d-d5d587100000 pid=4231 execve guuid=0976d6eb-1700-0000-fe5d-d5d59b100000 pid=4251 /usr/bin/chmod guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=0976d6eb-1700-0000-fe5d-d5d59b100000 pid=4251 execve guuid=b49d30ec-1700-0000-fe5d-d5d59d100000 pid=4253 /tmp/r2W guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=b49d30ec-1700-0000-fe5d-d5d59d100000 pid=4253 execve guuid=004e1dee-1700-0000-fe5d-d5d5a7100000 pid=4263 /usr/bin/rm guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=004e1dee-1700-0000-fe5d-d5d5a7100000 pid=4263 execve guuid=85ad62ee-1700-0000-fe5d-d5d5a8100000 pid=4264 /usr/bin/wget net send-data write-file guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=85ad62ee-1700-0000-fe5d-d5d5a8100000 pid=4264 execve guuid=1cb7e6f4-1700-0000-fe5d-d5d5bb100000 pid=4283 /usr/bin/chmod guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=1cb7e6f4-1700-0000-fe5d-d5d5bb100000 pid=4283 execve guuid=475249f5-1700-0000-fe5d-d5d5bd100000 pid=4285 /tmp/M2j9 guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=475249f5-1700-0000-fe5d-d5d5bd100000 pid=4285 execve guuid=ef97faf6-1700-0000-fe5d-d5d5c2100000 pid=4290 /usr/bin/rm guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ef97faf6-1700-0000-fe5d-d5d5c2100000 pid=4290 execve guuid=7d8f46f7-1700-0000-fe5d-d5d5c3100000 pid=4291 /usr/bin/wget net send-data write-file guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=7d8f46f7-1700-0000-fe5d-d5d5c3100000 pid=4291 execve guuid=ae7c60fd-1700-0000-fe5d-d5d5d8100000 pid=4312 /usr/bin/chmod guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=ae7c60fd-1700-0000-fe5d-d5d5d8100000 pid=4312 execve guuid=a9ef98fd-1700-0000-fe5d-d5d5d9100000 pid=4313 /tmp/VAZ guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=a9ef98fd-1700-0000-fe5d-d5d5d9100000 pid=4313 execve guuid=fffc43fe-1700-0000-fe5d-d5d5de100000 pid=4318 /usr/bin/rm delete-file guuid=113f8302-1700-0000-fe5d-d5d5980d0000 pid=3480->guuid=fffc43fe-1700-0000-fe5d-d5d5de100000 pid=4318 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=0934063a-1700-0000-fe5d-d5d5a20e0000 pid=3746->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=dec9c861-1700-0000-fe5d-d5d5e10e0000 pid=3809->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=fa9449e5-1700-0000-fe5d-d5d587100000 pid=4231->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=85ad62ee-1700-0000-fe5d-d5d5a8100000 pid=4264->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=7d8f46f7-1700-0000-fe5d-d5d5c3100000 pid=4291->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-10 01:03:46 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh dfcc7e51de3679d12f6d16464cd4e1d73734957f67fce02abe8d8ce1ff332b87

(this sample)

  
Delivery method
Distributed via web download

Comments