MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e21045d833b70f985f3f01daf5fadaaef1a960db0e3a55341bb9c13fca505047. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: e21045d833b70f985f3f01daf5fadaaef1a960db0e3a55341bb9c13fca505047
SHA3-384 hash: 13b606f70f5ecde456dbb0c8f53ba2e257d75751b3375773444a03b902ee44b6f4ce3ad5d2dbd2fd536ffc0c45545107
SHA1 hash: cd12ede299be1b380495610e07447f9f06849e42
MD5 hash: b4bf508eb6c826fcdcc380b556649bc9
humanhash: london-saturn-queen-speaker
File name:p
Download: download sample
File size:838 bytes
First seen:2026-06-18 10:10:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZoha7RFpSpeJjpOpD4XpN957:e9Qp+Ms7jpSpEjpOpEXpN957
TLSH T10B016FC68150AA1090AEA84E73DBB190B421D3C706471F5CBEDC552DEBD9514B115F98
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.225/yxxin/an/aua-wget
http://176.65.139.225/TAkn/an/aua-wget
http://176.65.139.225/tMZmn/an/aua-wget
http://176.65.139.225/gB3Nn/an/aua-wget
http://176.65.139.225/Xz68n/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=b92d7341-1a00-0000-4bec-efa4600c0000 pid=3168 /usr/bin/sudo guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174 /tmp/sample.bin write-file guuid=b92d7341-1a00-0000-4bec-efa4600c0000 pid=3168->guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174 execve guuid=16074c45-1a00-0000-4bec-efa4680c0000 pid=3176 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=16074c45-1a00-0000-4bec-efa4680c0000 pid=3176 execve guuid=dc6d3746-1a00-0000-4bec-efa46a0c0000 pid=3178 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=dc6d3746-1a00-0000-4bec-efa46a0c0000 pid=3178 execve guuid=1ab63d47-1a00-0000-4bec-efa46b0c0000 pid=3179 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=1ab63d47-1a00-0000-4bec-efa46b0c0000 pid=3179 execve guuid=878d3648-1a00-0000-4bec-efa46c0c0000 pid=3180 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=878d3648-1a00-0000-4bec-efa46c0c0000 pid=3180 execve guuid=41e5c748-1a00-0000-4bec-efa46d0c0000 pid=3181 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=41e5c748-1a00-0000-4bec-efa46d0c0000 pid=3181 execve guuid=d2a15749-1a00-0000-4bec-efa46f0c0000 pid=3183 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=d2a15749-1a00-0000-4bec-efa46f0c0000 pid=3183 execve guuid=c60cc849-1a00-0000-4bec-efa4700c0000 pid=3184 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c60cc849-1a00-0000-4bec-efa4700c0000 pid=3184 execve guuid=3015284a-1a00-0000-4bec-efa4720c0000 pid=3186 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3015284a-1a00-0000-4bec-efa4720c0000 pid=3186 execve guuid=862e914a-1a00-0000-4bec-efa4750c0000 pid=3189 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=862e914a-1a00-0000-4bec-efa4750c0000 pid=3189 execve guuid=ad0aef4a-1a00-0000-4bec-efa4770c0000 pid=3191 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=ad0aef4a-1a00-0000-4bec-efa4770c0000 pid=3191 execve guuid=80bd504b-1a00-0000-4bec-efa47a0c0000 pid=3194 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=80bd504b-1a00-0000-4bec-efa47a0c0000 pid=3194 execve guuid=84d6b84b-1a00-0000-4bec-efa47c0c0000 pid=3196 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=84d6b84b-1a00-0000-4bec-efa47c0c0000 pid=3196 execve guuid=8cff344d-1a00-0000-4bec-efa47d0c0000 pid=3197 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=8cff344d-1a00-0000-4bec-efa47d0c0000 pid=3197 execve guuid=8b86ba4d-1a00-0000-4bec-efa47f0c0000 pid=3199 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=8b86ba4d-1a00-0000-4bec-efa47f0c0000 pid=3199 execve guuid=98442b4e-1a00-0000-4bec-efa4820c0000 pid=3202 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=98442b4e-1a00-0000-4bec-efa4820c0000 pid=3202 execve guuid=a624b54e-1a00-0000-4bec-efa4840c0000 pid=3204 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=a624b54e-1a00-0000-4bec-efa4840c0000 pid=3204 execve guuid=f2fa314f-1a00-0000-4bec-efa4870c0000 pid=3207 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=f2fa314f-1a00-0000-4bec-efa4870c0000 pid=3207 execve guuid=6bd7cc4f-1a00-0000-4bec-efa4880c0000 pid=3208 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=6bd7cc4f-1a00-0000-4bec-efa4880c0000 pid=3208 execve guuid=e21a5150-1a00-0000-4bec-efa4890c0000 pid=3209 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e21a5150-1a00-0000-4bec-efa4890c0000 pid=3209 execve guuid=5c09d250-1a00-0000-4bec-efa48a0c0000 pid=3210 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=5c09d250-1a00-0000-4bec-efa48a0c0000 pid=3210 execve guuid=80593951-1a00-0000-4bec-efa48c0c0000 pid=3212 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=80593951-1a00-0000-4bec-efa48c0c0000 pid=3212 execve guuid=f7f6c651-1a00-0000-4bec-efa48d0c0000 pid=3213 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=f7f6c651-1a00-0000-4bec-efa48d0c0000 pid=3213 execve guuid=28203e52-1a00-0000-4bec-efa48e0c0000 pid=3214 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=28203e52-1a00-0000-4bec-efa48e0c0000 pid=3214 execve guuid=8637bd52-1a00-0000-4bec-efa4900c0000 pid=3216 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=8637bd52-1a00-0000-4bec-efa4900c0000 pid=3216 execve guuid=2db63553-1a00-0000-4bec-efa4920c0000 pid=3218 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2db63553-1a00-0000-4bec-efa4920c0000 pid=3218 execve guuid=47b29653-1a00-0000-4bec-efa4940c0000 pid=3220 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=47b29653-1a00-0000-4bec-efa4940c0000 pid=3220 execve guuid=94e33854-1a00-0000-4bec-efa4980c0000 pid=3224 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=94e33854-1a00-0000-4bec-efa4980c0000 pid=3224 execve guuid=e3274555-1a00-0000-4bec-efa4990c0000 pid=3225 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e3274555-1a00-0000-4bec-efa4990c0000 pid=3225 execve guuid=4a5d5656-1a00-0000-4bec-efa49a0c0000 pid=3226 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=4a5d5656-1a00-0000-4bec-efa49a0c0000 pid=3226 execve guuid=2c686157-1a00-0000-4bec-efa49b0c0000 pid=3227 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2c686157-1a00-0000-4bec-efa49b0c0000 pid=3227 execve guuid=2fb91b58-1a00-0000-4bec-efa49c0c0000 pid=3228 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2fb91b58-1a00-0000-4bec-efa49c0c0000 pid=3228 execve guuid=3f14ae58-1a00-0000-4bec-efa49d0c0000 pid=3229 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3f14ae58-1a00-0000-4bec-efa49d0c0000 pid=3229 execve guuid=77a84059-1a00-0000-4bec-efa49e0c0000 pid=3230 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=77a84059-1a00-0000-4bec-efa49e0c0000 pid=3230 execve guuid=f3b9d659-1a00-0000-4bec-efa4a00c0000 pid=3232 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=f3b9d659-1a00-0000-4bec-efa4a00c0000 pid=3232 execve guuid=4cf04c5a-1a00-0000-4bec-efa4a10c0000 pid=3233 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=4cf04c5a-1a00-0000-4bec-efa4a10c0000 pid=3233 execve guuid=630fc95a-1a00-0000-4bec-efa4a20c0000 pid=3234 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=630fc95a-1a00-0000-4bec-efa4a20c0000 pid=3234 execve guuid=a1b6355b-1a00-0000-4bec-efa4a30c0000 pid=3235 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=a1b6355b-1a00-0000-4bec-efa4a30c0000 pid=3235 execve guuid=6873975b-1a00-0000-4bec-efa4a50c0000 pid=3237 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=6873975b-1a00-0000-4bec-efa4a50c0000 pid=3237 execve guuid=6ac3ef5b-1a00-0000-4bec-efa4a70c0000 pid=3239 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=6ac3ef5b-1a00-0000-4bec-efa4a70c0000 pid=3239 execve guuid=35ec4d5c-1a00-0000-4bec-efa4a90c0000 pid=3241 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=35ec4d5c-1a00-0000-4bec-efa4a90c0000 pid=3241 execve guuid=9ef8af5c-1a00-0000-4bec-efa4ac0c0000 pid=3244 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=9ef8af5c-1a00-0000-4bec-efa4ac0c0000 pid=3244 execve guuid=12b6045d-1a00-0000-4bec-efa4ae0c0000 pid=3246 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=12b6045d-1a00-0000-4bec-efa4ae0c0000 pid=3246 execve guuid=66bc665d-1a00-0000-4bec-efa4b10c0000 pid=3249 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=66bc665d-1a00-0000-4bec-efa4b10c0000 pid=3249 execve guuid=e7dec45d-1a00-0000-4bec-efa4b30c0000 pid=3251 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e7dec45d-1a00-0000-4bec-efa4b30c0000 pid=3251 execve guuid=7e95365e-1a00-0000-4bec-efa4b60c0000 pid=3254 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7e95365e-1a00-0000-4bec-efa4b60c0000 pid=3254 execve guuid=bce0c55e-1a00-0000-4bec-efa4b90c0000 pid=3257 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=bce0c55e-1a00-0000-4bec-efa4b90c0000 pid=3257 execve guuid=e716585f-1a00-0000-4bec-efa4bc0c0000 pid=3260 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e716585f-1a00-0000-4bec-efa4bc0c0000 pid=3260 execve guuid=263bf35f-1a00-0000-4bec-efa4bf0c0000 pid=3263 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=263bf35f-1a00-0000-4bec-efa4bf0c0000 pid=3263 execve guuid=3195df60-1a00-0000-4bec-efa4c10c0000 pid=3265 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3195df60-1a00-0000-4bec-efa4c10c0000 pid=3265 execve guuid=9a91a361-1a00-0000-4bec-efa4c30c0000 pid=3267 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=9a91a361-1a00-0000-4bec-efa4c30c0000 pid=3267 execve guuid=cddd5862-1a00-0000-4bec-efa4c40c0000 pid=3268 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=cddd5862-1a00-0000-4bec-efa4c40c0000 pid=3268 execve guuid=06290b63-1a00-0000-4bec-efa4c70c0000 pid=3271 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=06290b63-1a00-0000-4bec-efa4c70c0000 pid=3271 execve guuid=3021aa63-1a00-0000-4bec-efa4ca0c0000 pid=3274 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3021aa63-1a00-0000-4bec-efa4ca0c0000 pid=3274 execve guuid=683cbd64-1a00-0000-4bec-efa4cd0c0000 pid=3277 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=683cbd64-1a00-0000-4bec-efa4cd0c0000 pid=3277 execve guuid=0ceb4b65-1a00-0000-4bec-efa4cf0c0000 pid=3279 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=0ceb4b65-1a00-0000-4bec-efa4cf0c0000 pid=3279 execve guuid=7e0fec65-1a00-0000-4bec-efa4d10c0000 pid=3281 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7e0fec65-1a00-0000-4bec-efa4d10c0000 pid=3281 execve guuid=86809066-1a00-0000-4bec-efa4d40c0000 pid=3284 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=86809066-1a00-0000-4bec-efa4d40c0000 pid=3284 execve guuid=c58e3267-1a00-0000-4bec-efa4d70c0000 pid=3287 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c58e3267-1a00-0000-4bec-efa4d70c0000 pid=3287 execve guuid=75c69c67-1a00-0000-4bec-efa4d90c0000 pid=3289 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=75c69c67-1a00-0000-4bec-efa4d90c0000 pid=3289 execve guuid=cf360568-1a00-0000-4bec-efa4db0c0000 pid=3291 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=cf360568-1a00-0000-4bec-efa4db0c0000 pid=3291 execve guuid=2c757868-1a00-0000-4bec-efa4dd0c0000 pid=3293 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2c757868-1a00-0000-4bec-efa4dd0c0000 pid=3293 execve guuid=e0b3de68-1a00-0000-4bec-efa4df0c0000 pid=3295 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e0b3de68-1a00-0000-4bec-efa4df0c0000 pid=3295 execve guuid=5b695569-1a00-0000-4bec-efa4e10c0000 pid=3297 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=5b695569-1a00-0000-4bec-efa4e10c0000 pid=3297 execve guuid=afd8c769-1a00-0000-4bec-efa4e30c0000 pid=3299 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=afd8c769-1a00-0000-4bec-efa4e30c0000 pid=3299 execve guuid=8bb6756a-1a00-0000-4bec-efa4e50c0000 pid=3301 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=8bb6756a-1a00-0000-4bec-efa4e50c0000 pid=3301 execve guuid=2ac3f86a-1a00-0000-4bec-efa4e60c0000 pid=3302 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2ac3f86a-1a00-0000-4bec-efa4e60c0000 pid=3302 execve guuid=d6366a6b-1a00-0000-4bec-efa4e70c0000 pid=3303 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=d6366a6b-1a00-0000-4bec-efa4e70c0000 pid=3303 execve guuid=8397e66b-1a00-0000-4bec-efa4e80c0000 pid=3304 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=8397e66b-1a00-0000-4bec-efa4e80c0000 pid=3304 execve guuid=cc40526c-1a00-0000-4bec-efa4ea0c0000 pid=3306 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=cc40526c-1a00-0000-4bec-efa4ea0c0000 pid=3306 execve guuid=2d40e36c-1a00-0000-4bec-efa4ed0c0000 pid=3309 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2d40e36c-1a00-0000-4bec-efa4ed0c0000 pid=3309 execve guuid=7107746d-1a00-0000-4bec-efa4f00c0000 pid=3312 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7107746d-1a00-0000-4bec-efa4f00c0000 pid=3312 execve guuid=2812f16d-1a00-0000-4bec-efa4f20c0000 pid=3314 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2812f16d-1a00-0000-4bec-efa4f20c0000 pid=3314 execve guuid=a583696e-1a00-0000-4bec-efa4f30c0000 pid=3315 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=a583696e-1a00-0000-4bec-efa4f30c0000 pid=3315 execve guuid=1ffae16e-1a00-0000-4bec-efa4f40c0000 pid=3316 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=1ffae16e-1a00-0000-4bec-efa4f40c0000 pid=3316 execve guuid=ab81666f-1a00-0000-4bec-efa4f60c0000 pid=3318 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=ab81666f-1a00-0000-4bec-efa4f60c0000 pid=3318 execve guuid=8edb0970-1a00-0000-4bec-efa4f70c0000 pid=3319 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=8edb0970-1a00-0000-4bec-efa4f70c0000 pid=3319 execve guuid=77a1d570-1a00-0000-4bec-efa4f80c0000 pid=3320 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=77a1d570-1a00-0000-4bec-efa4f80c0000 pid=3320 execve guuid=07014571-1a00-0000-4bec-efa4fb0c0000 pid=3323 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=07014571-1a00-0000-4bec-efa4fb0c0000 pid=3323 execve guuid=ca2cb471-1a00-0000-4bec-efa4fe0c0000 pid=3326 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=ca2cb471-1a00-0000-4bec-efa4fe0c0000 pid=3326 execve guuid=12c94b72-1a00-0000-4bec-efa4010d0000 pid=3329 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=12c94b72-1a00-0000-4bec-efa4010d0000 pid=3329 execve guuid=195ef572-1a00-0000-4bec-efa4040d0000 pid=3332 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=195ef572-1a00-0000-4bec-efa4040d0000 pid=3332 execve guuid=20335a73-1a00-0000-4bec-efa4060d0000 pid=3334 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=20335a73-1a00-0000-4bec-efa4060d0000 pid=3334 execve guuid=f85bbf73-1a00-0000-4bec-efa4090d0000 pid=3337 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=f85bbf73-1a00-0000-4bec-efa4090d0000 pid=3337 execve guuid=81cc2174-1a00-0000-4bec-efa40b0d0000 pid=3339 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=81cc2174-1a00-0000-4bec-efa40b0d0000 pid=3339 execve guuid=07367d74-1a00-0000-4bec-efa40e0d0000 pid=3342 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=07367d74-1a00-0000-4bec-efa40e0d0000 pid=3342 execve guuid=147bd874-1a00-0000-4bec-efa4100d0000 pid=3344 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=147bd874-1a00-0000-4bec-efa4100d0000 pid=3344 execve guuid=99603175-1a00-0000-4bec-efa4120d0000 pid=3346 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=99603175-1a00-0000-4bec-efa4120d0000 pid=3346 execve guuid=51388e75-1a00-0000-4bec-efa4150d0000 pid=3349 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=51388e75-1a00-0000-4bec-efa4150d0000 pid=3349 execve guuid=d7a8ed75-1a00-0000-4bec-efa4160d0000 pid=3350 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=d7a8ed75-1a00-0000-4bec-efa4160d0000 pid=3350 execve guuid=c3ae4776-1a00-0000-4bec-efa4180d0000 pid=3352 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c3ae4776-1a00-0000-4bec-efa4180d0000 pid=3352 execve guuid=2048be76-1a00-0000-4bec-efa4190d0000 pid=3353 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2048be76-1a00-0000-4bec-efa4190d0000 pid=3353 execve guuid=4e602f77-1a00-0000-4bec-efa41a0d0000 pid=3354 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=4e602f77-1a00-0000-4bec-efa41a0d0000 pid=3354 execve guuid=06629c77-1a00-0000-4bec-efa41b0d0000 pid=3355 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=06629c77-1a00-0000-4bec-efa41b0d0000 pid=3355 execve guuid=a8431678-1a00-0000-4bec-efa41c0d0000 pid=3356 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=a8431678-1a00-0000-4bec-efa41c0d0000 pid=3356 execve guuid=3cb78778-1a00-0000-4bec-efa41f0d0000 pid=3359 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3cb78778-1a00-0000-4bec-efa41f0d0000 pid=3359 execve guuid=9ff4f378-1a00-0000-4bec-efa4210d0000 pid=3361 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=9ff4f378-1a00-0000-4bec-efa4210d0000 pid=3361 execve guuid=66cd6379-1a00-0000-4bec-efa4230d0000 pid=3363 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=66cd6379-1a00-0000-4bec-efa4230d0000 pid=3363 execve guuid=d228ce79-1a00-0000-4bec-efa4250d0000 pid=3365 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=d228ce79-1a00-0000-4bec-efa4250d0000 pid=3365 execve guuid=bd16337a-1a00-0000-4bec-efa4270d0000 pid=3367 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=bd16337a-1a00-0000-4bec-efa4270d0000 pid=3367 execve guuid=f049b27a-1a00-0000-4bec-efa4280d0000 pid=3368 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=f049b27a-1a00-0000-4bec-efa4280d0000 pid=3368 execve guuid=63224a7b-1a00-0000-4bec-efa4290d0000 pid=3369 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=63224a7b-1a00-0000-4bec-efa4290d0000 pid=3369 execve guuid=fd7cdd7b-1a00-0000-4bec-efa42a0d0000 pid=3370 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=fd7cdd7b-1a00-0000-4bec-efa42a0d0000 pid=3370 execve guuid=22bc6f7c-1a00-0000-4bec-efa42b0d0000 pid=3371 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=22bc6f7c-1a00-0000-4bec-efa42b0d0000 pid=3371 execve guuid=558c057d-1a00-0000-4bec-efa42c0d0000 pid=3372 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=558c057d-1a00-0000-4bec-efa42c0d0000 pid=3372 execve guuid=7dada27d-1a00-0000-4bec-efa42d0d0000 pid=3373 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7dada27d-1a00-0000-4bec-efa42d0d0000 pid=3373 execve guuid=2a48277e-1a00-0000-4bec-efa42e0d0000 pid=3374 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2a48277e-1a00-0000-4bec-efa42e0d0000 pid=3374 execve guuid=af32ac7e-1a00-0000-4bec-efa42f0d0000 pid=3375 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=af32ac7e-1a00-0000-4bec-efa42f0d0000 pid=3375 execve guuid=7940287f-1a00-0000-4bec-efa4300d0000 pid=3376 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7940287f-1a00-0000-4bec-efa4300d0000 pid=3376 execve guuid=ed8cb67f-1a00-0000-4bec-efa4310d0000 pid=3377 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=ed8cb67f-1a00-0000-4bec-efa4310d0000 pid=3377 execve guuid=98925e80-1a00-0000-4bec-efa4320d0000 pid=3378 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=98925e80-1a00-0000-4bec-efa4320d0000 pid=3378 execve guuid=7f4a4881-1a00-0000-4bec-efa4330d0000 pid=3379 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7f4a4881-1a00-0000-4bec-efa4330d0000 pid=3379 execve guuid=c8613c82-1a00-0000-4bec-efa4340d0000 pid=3380 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c8613c82-1a00-0000-4bec-efa4340d0000 pid=3380 execve guuid=e5043583-1a00-0000-4bec-efa4350d0000 pid=3381 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e5043583-1a00-0000-4bec-efa4350d0000 pid=3381 execve guuid=30691084-1a00-0000-4bec-efa4360d0000 pid=3382 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=30691084-1a00-0000-4bec-efa4360d0000 pid=3382 execve guuid=3391c984-1a00-0000-4bec-efa4370d0000 pid=3383 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3391c984-1a00-0000-4bec-efa4370d0000 pid=3383 execve guuid=9a9e6e85-1a00-0000-4bec-efa4380d0000 pid=3384 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=9a9e6e85-1a00-0000-4bec-efa4380d0000 pid=3384 execve guuid=642ae585-1a00-0000-4bec-efa43a0d0000 pid=3386 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=642ae585-1a00-0000-4bec-efa43a0d0000 pid=3386 execve guuid=c1ae7386-1a00-0000-4bec-efa43b0d0000 pid=3387 /usr/bin/ls guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c1ae7386-1a00-0000-4bec-efa43b0d0000 pid=3387 execve guuid=92bded86-1a00-0000-4bec-efa43d0d0000 pid=3389 /usr/bin/rm guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=92bded86-1a00-0000-4bec-efa43d0d0000 pid=3389 execve guuid=35294587-1a00-0000-4bec-efa43f0d0000 pid=3391 /usr/bin/wget net send-data write-file guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=35294587-1a00-0000-4bec-efa43f0d0000 pid=3391 execve guuid=e12a048c-1a00-0000-4bec-efa44c0d0000 pid=3404 /usr/bin/chmod guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e12a048c-1a00-0000-4bec-efa44c0d0000 pid=3404 execve guuid=ad98658c-1a00-0000-4bec-efa44d0d0000 pid=3405 /tmp/yxxi guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=ad98658c-1a00-0000-4bec-efa44d0d0000 pid=3405 execve guuid=fc9b298d-1a00-0000-4bec-efa4520d0000 pid=3410 /usr/bin/rm guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=fc9b298d-1a00-0000-4bec-efa4520d0000 pid=3410 execve guuid=2bfd668d-1a00-0000-4bec-efa4530d0000 pid=3411 /usr/bin/wget net send-data write-file guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=2bfd668d-1a00-0000-4bec-efa4530d0000 pid=3411 execve guuid=1d4e1190-1a00-0000-4bec-efa45b0d0000 pid=3419 /usr/bin/chmod guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=1d4e1190-1a00-0000-4bec-efa45b0d0000 pid=3419 execve guuid=7b0da490-1a00-0000-4bec-efa45d0d0000 pid=3421 /tmp/TAk guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=7b0da490-1a00-0000-4bec-efa45d0d0000 pid=3421 execve guuid=0afe8592-1a00-0000-4bec-efa4620d0000 pid=3426 /usr/bin/rm guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=0afe8592-1a00-0000-4bec-efa4620d0000 pid=3426 execve guuid=3bced292-1a00-0000-4bec-efa4640d0000 pid=3428 /usr/bin/wget net send-data write-file guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=3bced292-1a00-0000-4bec-efa4640d0000 pid=3428 execve guuid=c3afea95-1a00-0000-4bec-efa46b0d0000 pid=3435 /usr/bin/chmod guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c3afea95-1a00-0000-4bec-efa46b0d0000 pid=3435 execve guuid=93de3096-1a00-0000-4bec-efa46d0d0000 pid=3437 /tmp/tMZm guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=93de3096-1a00-0000-4bec-efa46d0d0000 pid=3437 execve guuid=ab0e7d98-1a00-0000-4bec-efa4720d0000 pid=3442 /usr/bin/rm guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=ab0e7d98-1a00-0000-4bec-efa4720d0000 pid=3442 execve guuid=c7a1d498-1a00-0000-4bec-efa4730d0000 pid=3443 /usr/bin/wget net send-data write-file guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=c7a1d498-1a00-0000-4bec-efa4730d0000 pid=3443 execve guuid=48fcb99b-1a00-0000-4bec-efa47a0d0000 pid=3450 /usr/bin/chmod guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=48fcb99b-1a00-0000-4bec-efa47a0d0000 pid=3450 execve guuid=e7bd1f9c-1a00-0000-4bec-efa47b0d0000 pid=3451 /tmp/gB3N guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=e7bd1f9c-1a00-0000-4bec-efa47b0d0000 pid=3451 execve guuid=95d0359d-1a00-0000-4bec-efa4810d0000 pid=3457 /usr/bin/rm guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=95d0359d-1a00-0000-4bec-efa4810d0000 pid=3457 execve guuid=65cc789d-1a00-0000-4bec-efa4830d0000 pid=3459 /usr/bin/wget net send-data write-file guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=65cc789d-1a00-0000-4bec-efa4830d0000 pid=3459 execve guuid=d3bc20a0-1a00-0000-4bec-efa48b0d0000 pid=3467 /usr/bin/chmod guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=d3bc20a0-1a00-0000-4bec-efa48b0d0000 pid=3467 execve guuid=86a98aa0-1a00-0000-4bec-efa48d0d0000 pid=3469 /tmp/Xz68 guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=86a98aa0-1a00-0000-4bec-efa48d0d0000 pid=3469 execve guuid=76acc6a1-1a00-0000-4bec-efa4920d0000 pid=3474 /usr/bin/rm delete-file guuid=131af844-1a00-0000-4bec-efa4660c0000 pid=3174->guuid=76acc6a1-1a00-0000-4bec-efa4920d0000 pid=3474 execve f7004531-0900-5fd6-a416-c42b6ce9fcc5 176.65.139.225:80 guuid=35294587-1a00-0000-4bec-efa43f0d0000 pid=3391->f7004531-0900-5fd6-a416-c42b6ce9fcc5 send: 133B guuid=2bfd668d-1a00-0000-4bec-efa4530d0000 pid=3411->f7004531-0900-5fd6-a416-c42b6ce9fcc5 send: 132B guuid=3bced292-1a00-0000-4bec-efa4640d0000 pid=3428->f7004531-0900-5fd6-a416-c42b6ce9fcc5 send: 133B guuid=c7a1d498-1a00-0000-4bec-efa4730d0000 pid=3443->f7004531-0900-5fd6-a416-c42b6ce9fcc5 send: 133B guuid=65cc789d-1a00-0000-4bec-efa4830d0000 pid=3459->f7004531-0900-5fd6-a416-c42b6ce9fcc5 send: 133B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-18 10:12:09 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e21045d833b70f985f3f01daf5fadaaef1a960db0e3a55341bb9c13fca505047

(this sample)

  
Delivery method
Distributed via web download

Comments