MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e06d6e5b8457a293a75bacdbfa6ae55874f74562ad27e25d69f0f509b7f8641c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e06d6e5b8457a293a75bacdbfa6ae55874f74562ad27e25d69f0f509b7f8641c
SHA3-384 hash: 7c2554e6305b55024406b3abc01fee8acfc9b7c46f53de674f5807801157dcdd3ba9648ddcde534f3822255cc43003fd
SHA1 hash: 8bb8a4ac3b1dd52a6115d1d4af27e21445c5b34e
MD5 hash: 254d437c9f55fba8531a86d5c0301123
humanhash: harry-oranges-monkey-gee
File name:c.sh
Download: download sample
File size:778 bytes
First seen:2026-01-20 19:14:10 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3mKXMUYNI7KQfKX2DxssuDku7+tBWssJZszHR:J8k/fFDcUaIzx
TLSH T10B01DEAD22D5A187DA0C8F58F16A827C6BCACAD4F0741DD5F1548C70A9DE610306DB7A
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=fd3bbc14-1800-0000-8aa2-acd3550c0000 pid=3157 /usr/bin/sudo guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161 /tmp/sample.bin guuid=fd3bbc14-1800-0000-8aa2-acd3550c0000 pid=3157->guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161 execve guuid=72e25317-1800-0000-8aa2-acd35b0c0000 pid=3163 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=72e25317-1800-0000-8aa2-acd35b0c0000 pid=3163 execve guuid=e5e3a155-1800-0000-8aa2-acd38b0c0000 pid=3211 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=e5e3a155-1800-0000-8aa2-acd38b0c0000 pid=3211 execve guuid=aef8f855-1800-0000-8aa2-acd38c0c0000 pid=3212 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=aef8f855-1800-0000-8aa2-acd38c0c0000 pid=3212 clone guuid=884f0756-1800-0000-8aa2-acd38d0c0000 pid=3213 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=884f0756-1800-0000-8aa2-acd38d0c0000 pid=3213 execve guuid=113e1686-1800-0000-8aa2-acd3d70c0000 pid=3287 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=113e1686-1800-0000-8aa2-acd3d70c0000 pid=3287 execve guuid=3ef69986-1800-0000-8aa2-acd3da0c0000 pid=3290 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=3ef69986-1800-0000-8aa2-acd3da0c0000 pid=3290 clone guuid=0e13a986-1800-0000-8aa2-acd3db0c0000 pid=3291 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=0e13a986-1800-0000-8aa2-acd3db0c0000 pid=3291 execve guuid=379b0dbe-1800-0000-8aa2-acd34e0d0000 pid=3406 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=379b0dbe-1800-0000-8aa2-acd34e0d0000 pid=3406 execve guuid=1a5b6ebe-1800-0000-8aa2-acd3500d0000 pid=3408 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=1a5b6ebe-1800-0000-8aa2-acd3500d0000 pid=3408 clone guuid=543b73be-1800-0000-8aa2-acd3510d0000 pid=3409 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=543b73be-1800-0000-8aa2-acd3510d0000 pid=3409 execve guuid=01a89f13-1900-0000-8aa2-acd3060e0000 pid=3590 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=01a89f13-1900-0000-8aa2-acd3060e0000 pid=3590 execve guuid=2ddfe013-1900-0000-8aa2-acd3080e0000 pid=3592 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=2ddfe013-1900-0000-8aa2-acd3080e0000 pid=3592 clone guuid=3490f613-1900-0000-8aa2-acd3090e0000 pid=3593 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=3490f613-1900-0000-8aa2-acd3090e0000 pid=3593 execve guuid=ba44de49-1900-0000-8aa2-acd37c0e0000 pid=3708 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=ba44de49-1900-0000-8aa2-acd37c0e0000 pid=3708 execve guuid=27f5574a-1900-0000-8aa2-acd37f0e0000 pid=3711 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=27f5574a-1900-0000-8aa2-acd37f0e0000 pid=3711 clone guuid=0851754a-1900-0000-8aa2-acd3800e0000 pid=3712 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=0851754a-1900-0000-8aa2-acd3800e0000 pid=3712 execve guuid=abde0387-1900-0000-8aa2-acd3510f0000 pid=3921 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=abde0387-1900-0000-8aa2-acd3510f0000 pid=3921 execve guuid=97936b87-1900-0000-8aa2-acd3530f0000 pid=3923 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=97936b87-1900-0000-8aa2-acd3530f0000 pid=3923 clone guuid=e0fb7987-1900-0000-8aa2-acd3540f0000 pid=3924 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=e0fb7987-1900-0000-8aa2-acd3540f0000 pid=3924 execve guuid=0cee81c3-1900-0000-8aa2-acd31e100000 pid=4126 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=0cee81c3-1900-0000-8aa2-acd31e100000 pid=4126 execve guuid=0cb1edc3-1900-0000-8aa2-acd320100000 pid=4128 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=0cb1edc3-1900-0000-8aa2-acd320100000 pid=4128 clone guuid=e11a01c4-1900-0000-8aa2-acd321100000 pid=4129 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=e11a01c4-1900-0000-8aa2-acd321100000 pid=4129 execve guuid=044fc1fc-1900-0000-8aa2-acd3d2100000 pid=4306 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=044fc1fc-1900-0000-8aa2-acd3d2100000 pid=4306 execve guuid=8f1144fd-1900-0000-8aa2-acd3d7100000 pid=4311 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=8f1144fd-1900-0000-8aa2-acd3d7100000 pid=4311 clone guuid=4a4952fd-1900-0000-8aa2-acd3d8100000 pid=4312 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=4a4952fd-1900-0000-8aa2-acd3d8100000 pid=4312 execve guuid=54123337-1a00-0000-8aa2-acd399110000 pid=4505 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=54123337-1a00-0000-8aa2-acd399110000 pid=4505 execve guuid=31af9d37-1a00-0000-8aa2-acd39b110000 pid=4507 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=31af9d37-1a00-0000-8aa2-acd39b110000 pid=4507 clone guuid=1306ae37-1a00-0000-8aa2-acd39d110000 pid=4509 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=1306ae37-1a00-0000-8aa2-acd39d110000 pid=4509 execve guuid=bb9b2d72-1a00-0000-8aa2-acd346120000 pid=4678 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=bb9b2d72-1a00-0000-8aa2-acd346120000 pid=4678 execve guuid=738ba872-1a00-0000-8aa2-acd348120000 pid=4680 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=738ba872-1a00-0000-8aa2-acd348120000 pid=4680 clone guuid=0052c672-1a00-0000-8aa2-acd349120000 pid=4681 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=0052c672-1a00-0000-8aa2-acd349120000 pid=4681 execve guuid=b20b7eae-1a00-0000-8aa2-acd3e3120000 pid=4835 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=b20b7eae-1a00-0000-8aa2-acd3e3120000 pid=4835 execve guuid=5511d1ae-1a00-0000-8aa2-acd3e5120000 pid=4837 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=5511d1ae-1a00-0000-8aa2-acd3e5120000 pid=4837 clone guuid=7c8cdbae-1a00-0000-8aa2-acd3e6120000 pid=4838 /usr/bin/curl net send-data guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=7c8cdbae-1a00-0000-8aa2-acd3e6120000 pid=4838 execve guuid=a3cdc3e7-1a00-0000-8aa2-acd39a130000 pid=5018 /usr/bin/chmod guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=a3cdc3e7-1a00-0000-8aa2-acd39a130000 pid=5018 execve guuid=85d00be8-1a00-0000-8aa2-acd39c130000 pid=5020 /usr/bin/dash guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=85d00be8-1a00-0000-8aa2-acd39c130000 pid=5020 clone guuid=c60f15e8-1a00-0000-8aa2-acd39d130000 pid=5021 /usr/bin/rm delete-file guuid=5a9aed16-1800-0000-8aa2-acd3590c0000 pid=3161->guuid=c60f15e8-1a00-0000-8aa2-acd39d130000 pid=5021 execve e9272886-a735-5495-acea-11202e0d0fe3 103.124.93.149:80 guuid=72e25317-1800-0000-8aa2-acd35b0c0000 pid=3163->e9272886-a735-5495-acea-11202e0d0fe3 send: 81B guuid=884f0756-1800-0000-8aa2-acd38d0c0000 pid=3213->e9272886-a735-5495-acea-11202e0d0fe3 send: 82B guuid=0e13a986-1800-0000-8aa2-acd3db0c0000 pid=3291->e9272886-a735-5495-acea-11202e0d0fe3 send: 82B guuid=543b73be-1800-0000-8aa2-acd3510d0000 pid=3409->e9272886-a735-5495-acea-11202e0d0fe3 send: 82B guuid=3490f613-1900-0000-8aa2-acd3090e0000 pid=3593->e9272886-a735-5495-acea-11202e0d0fe3 send: 82B guuid=0851754a-1900-0000-8aa2-acd3800e0000 pid=3712->e9272886-a735-5495-acea-11202e0d0fe3 send: 82B guuid=e0fb7987-1900-0000-8aa2-acd3540f0000 pid=3924->e9272886-a735-5495-acea-11202e0d0fe3 send: 82B guuid=e11a01c4-1900-0000-8aa2-acd321100000 pid=4129->e9272886-a735-5495-acea-11202e0d0fe3 send: 81B guuid=4a4952fd-1900-0000-8aa2-acd3d8100000 pid=4312->e9272886-a735-5495-acea-11202e0d0fe3 send: 81B guuid=1306ae37-1a00-0000-8aa2-acd39d110000 pid=4509->e9272886-a735-5495-acea-11202e0d0fe3 send: 81B guuid=0052c672-1a00-0000-8aa2-acd349120000 pid=4681->e9272886-a735-5495-acea-11202e0d0fe3 send: 81B guuid=7c8cdbae-1a00-0000-8aa2-acd3e6120000 pid=4838->e9272886-a735-5495-acea-11202e0d0fe3 send: 84B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Alevaul
Status:
Malicious
First seen:
2026-01-20 15:41:49 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e06d6e5b8457a293a75bacdbfa6ae55874f74562ad27e25d69f0f509b7f8641c

(this sample)

  
Delivery method
Distributed via web download

Comments