MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ecb432b0f7344e66dbdb68d21819284264db3707941f0c8ea95db0abcb26e595. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: ecb432b0f7344e66dbdb68d21819284264db3707941f0c8ea95db0abcb26e595
SHA3-384 hash: f7059c622f6f9fc856693ca5294999ca52d0c972e502f4a3d312547f2e6cc7ec618734d99f14e066b68dad751dba8131
SHA1 hash: ca76507c8f067a22aa1fa25bd298ea288ab8bdb9
MD5 hash: b12782a5431c30260a8e708c4697837e
humanhash: delaware-speaker-massachusetts-king
File name:lil
Download: download sample
File size:835 bytes
First seen:2026-06-07 13:53:07 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkarIO4FxIDsjIckxg/XITVzDI7nIX:kXCKysE2hi0ziQvZohar+j/Xi5AIX
TLSH T15D01C2CEC015DB9050C5E89D36A75144F810C3CB26568F7CBE5C583E8B75B487056F94
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/pkMn/an/aelf ua-wget
http://188.132.232.81/9QPn/an/aelf ua-wget
http://188.132.232.81/bA5on/an/aelf ua-wget
http://188.132.232.81/Jj0n/an/aelf ua-wget
http://188.132.232.81/gGBn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-07T11:02:00Z UTC
Last seen:
2026-06-07T11:25:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=84786db5-1800-0000-6c50-3137660c0000 pid=3174 /usr/bin/sudo guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175 /tmp/sample.bin write-file guuid=84786db5-1800-0000-6c50-3137660c0000 pid=3174->guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175 execve guuid=554d1fb8-1800-0000-6c50-3137680c0000 pid=3176 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=554d1fb8-1800-0000-6c50-3137680c0000 pid=3176 execve guuid=2299bbb8-1800-0000-6c50-3137690c0000 pid=3177 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2299bbb8-1800-0000-6c50-3137690c0000 pid=3177 execve guuid=b27e44b9-1800-0000-6c50-31376a0c0000 pid=3178 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=b27e44b9-1800-0000-6c50-31376a0c0000 pid=3178 execve guuid=eb1dd0b9-1800-0000-6c50-31376b0c0000 pid=3179 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=eb1dd0b9-1800-0000-6c50-31376b0c0000 pid=3179 execve guuid=df866cba-1800-0000-6c50-31376c0c0000 pid=3180 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=df866cba-1800-0000-6c50-31376c0c0000 pid=3180 execve guuid=7f0e2fbb-1800-0000-6c50-31376d0c0000 pid=3181 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=7f0e2fbb-1800-0000-6c50-31376d0c0000 pid=3181 execve guuid=851de9bb-1800-0000-6c50-31376e0c0000 pid=3182 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=851de9bb-1800-0000-6c50-31376e0c0000 pid=3182 execve guuid=a8709abc-1800-0000-6c50-31376f0c0000 pid=3183 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=a8709abc-1800-0000-6c50-31376f0c0000 pid=3183 execve guuid=548e75bd-1800-0000-6c50-3137700c0000 pid=3184 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=548e75bd-1800-0000-6c50-3137700c0000 pid=3184 execve guuid=c8b005be-1800-0000-6c50-3137710c0000 pid=3185 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c8b005be-1800-0000-6c50-3137710c0000 pid=3185 execve guuid=7f0895be-1800-0000-6c50-3137720c0000 pid=3186 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=7f0895be-1800-0000-6c50-3137720c0000 pid=3186 execve guuid=e8c033bf-1800-0000-6c50-3137730c0000 pid=3187 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e8c033bf-1800-0000-6c50-3137730c0000 pid=3187 execve guuid=cfe8d4bf-1800-0000-6c50-3137740c0000 pid=3188 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=cfe8d4bf-1800-0000-6c50-3137740c0000 pid=3188 execve guuid=c8db5bc0-1800-0000-6c50-3137750c0000 pid=3189 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c8db5bc0-1800-0000-6c50-3137750c0000 pid=3189 execve guuid=b94edfc0-1800-0000-6c50-3137760c0000 pid=3190 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=b94edfc0-1800-0000-6c50-3137760c0000 pid=3190 execve guuid=55fa61c1-1800-0000-6c50-3137770c0000 pid=3191 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=55fa61c1-1800-0000-6c50-3137770c0000 pid=3191 execve guuid=681fefc1-1800-0000-6c50-3137780c0000 pid=3192 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=681fefc1-1800-0000-6c50-3137780c0000 pid=3192 execve guuid=ae41abc2-1800-0000-6c50-31377a0c0000 pid=3194 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=ae41abc2-1800-0000-6c50-31377a0c0000 pid=3194 execve guuid=076e90c3-1800-0000-6c50-31377b0c0000 pid=3195 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=076e90c3-1800-0000-6c50-31377b0c0000 pid=3195 execve guuid=df6566c4-1800-0000-6c50-31377d0c0000 pid=3197 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=df6566c4-1800-0000-6c50-31377d0c0000 pid=3197 execve guuid=dbf111c5-1800-0000-6c50-31377f0c0000 pid=3199 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=dbf111c5-1800-0000-6c50-31377f0c0000 pid=3199 execve guuid=591cb9c5-1800-0000-6c50-3137820c0000 pid=3202 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=591cb9c5-1800-0000-6c50-3137820c0000 pid=3202 execve guuid=2e3c5fc6-1800-0000-6c50-3137840c0000 pid=3204 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2e3c5fc6-1800-0000-6c50-3137840c0000 pid=3204 execve guuid=acfcfbc6-1800-0000-6c50-3137870c0000 pid=3207 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=acfcfbc6-1800-0000-6c50-3137870c0000 pid=3207 execve guuid=64c69dc7-1800-0000-6c50-3137890c0000 pid=3209 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=64c69dc7-1800-0000-6c50-3137890c0000 pid=3209 execve guuid=945b3dc8-1800-0000-6c50-31378b0c0000 pid=3211 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=945b3dc8-1800-0000-6c50-31378b0c0000 pid=3211 execve guuid=38e5e3c8-1800-0000-6c50-31378c0c0000 pid=3212 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=38e5e3c8-1800-0000-6c50-31378c0c0000 pid=3212 execve guuid=505387c9-1800-0000-6c50-31378f0c0000 pid=3215 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=505387c9-1800-0000-6c50-31378f0c0000 pid=3215 execve guuid=a69621ca-1800-0000-6c50-3137910c0000 pid=3217 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=a69621ca-1800-0000-6c50-3137910c0000 pid=3217 execve guuid=c7d802cb-1800-0000-6c50-3137940c0000 pid=3220 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c7d802cb-1800-0000-6c50-3137940c0000 pid=3220 execve guuid=742a75cb-1800-0000-6c50-3137960c0000 pid=3222 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=742a75cb-1800-0000-6c50-3137960c0000 pid=3222 execve guuid=6edf08cc-1800-0000-6c50-3137990c0000 pid=3225 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=6edf08cc-1800-0000-6c50-3137990c0000 pid=3225 execve guuid=c258a3cc-1800-0000-6c50-31379a0c0000 pid=3226 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c258a3cc-1800-0000-6c50-31379a0c0000 pid=3226 execve guuid=26b23fcd-1800-0000-6c50-31379b0c0000 pid=3227 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=26b23fcd-1800-0000-6c50-31379b0c0000 pid=3227 execve guuid=0f0e08ce-1800-0000-6c50-31379c0c0000 pid=3228 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=0f0e08ce-1800-0000-6c50-31379c0c0000 pid=3228 execve guuid=d5e591ce-1800-0000-6c50-31379d0c0000 pid=3229 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=d5e591ce-1800-0000-6c50-31379d0c0000 pid=3229 execve guuid=4a9e33cf-1800-0000-6c50-31379e0c0000 pid=3230 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=4a9e33cf-1800-0000-6c50-31379e0c0000 pid=3230 execve guuid=101cc2cf-1800-0000-6c50-31379f0c0000 pid=3231 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=101cc2cf-1800-0000-6c50-31379f0c0000 pid=3231 execve guuid=4ffd7dd0-1800-0000-6c50-3137a10c0000 pid=3233 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=4ffd7dd0-1800-0000-6c50-3137a10c0000 pid=3233 execve guuid=5685fcd0-1800-0000-6c50-3137a30c0000 pid=3235 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=5685fcd0-1800-0000-6c50-3137a30c0000 pid=3235 execve guuid=fb6c8dd1-1800-0000-6c50-3137a50c0000 pid=3237 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=fb6c8dd1-1800-0000-6c50-3137a50c0000 pid=3237 execve guuid=582800d2-1800-0000-6c50-3137a80c0000 pid=3240 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=582800d2-1800-0000-6c50-3137a80c0000 pid=3240 execve guuid=a0bc67d2-1800-0000-6c50-3137aa0c0000 pid=3242 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=a0bc67d2-1800-0000-6c50-3137aa0c0000 pid=3242 execve guuid=a765d4d2-1800-0000-6c50-3137ac0c0000 pid=3244 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=a765d4d2-1800-0000-6c50-3137ac0c0000 pid=3244 execve guuid=401c5fd3-1800-0000-6c50-3137ad0c0000 pid=3245 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=401c5fd3-1800-0000-6c50-3137ad0c0000 pid=3245 execve guuid=e1f9fed3-1800-0000-6c50-3137ae0c0000 pid=3246 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e1f9fed3-1800-0000-6c50-3137ae0c0000 pid=3246 execve guuid=70a960d4-1800-0000-6c50-3137b00c0000 pid=3248 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=70a960d4-1800-0000-6c50-3137b00c0000 pid=3248 execve guuid=3ed0c5d4-1800-0000-6c50-3137b10c0000 pid=3249 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=3ed0c5d4-1800-0000-6c50-3137b10c0000 pid=3249 execve guuid=ed8231d5-1800-0000-6c50-3137b40c0000 pid=3252 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=ed8231d5-1800-0000-6c50-3137b40c0000 pid=3252 execve guuid=e4f29bd5-1800-0000-6c50-3137b60c0000 pid=3254 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e4f29bd5-1800-0000-6c50-3137b60c0000 pid=3254 execve guuid=dc0137d6-1800-0000-6c50-3137b90c0000 pid=3257 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=dc0137d6-1800-0000-6c50-3137b90c0000 pid=3257 execve guuid=3ce4f6d6-1800-0000-6c50-3137bb0c0000 pid=3259 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=3ce4f6d6-1800-0000-6c50-3137bb0c0000 pid=3259 execve guuid=9d2450d7-1800-0000-6c50-3137be0c0000 pid=3262 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=9d2450d7-1800-0000-6c50-3137be0c0000 pid=3262 execve guuid=a45aadd7-1800-0000-6c50-3137c00c0000 pid=3264 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=a45aadd7-1800-0000-6c50-3137c00c0000 pid=3264 execve guuid=21bf34d8-1800-0000-6c50-3137c20c0000 pid=3266 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=21bf34d8-1800-0000-6c50-3137c20c0000 pid=3266 execve guuid=fe3cbad8-1800-0000-6c50-3137c30c0000 pid=3267 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=fe3cbad8-1800-0000-6c50-3137c30c0000 pid=3267 execve guuid=430834d9-1800-0000-6c50-3137c40c0000 pid=3268 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=430834d9-1800-0000-6c50-3137c40c0000 pid=3268 execve guuid=2411b7d9-1800-0000-6c50-3137c50c0000 pid=3269 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2411b7d9-1800-0000-6c50-3137c50c0000 pid=3269 execve guuid=c14327da-1800-0000-6c50-3137c60c0000 pid=3270 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c14327da-1800-0000-6c50-3137c60c0000 pid=3270 execve guuid=3dccb7da-1800-0000-6c50-3137c70c0000 pid=3271 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=3dccb7da-1800-0000-6c50-3137c70c0000 pid=3271 execve guuid=e1b452db-1800-0000-6c50-3137c80c0000 pid=3272 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e1b452db-1800-0000-6c50-3137c80c0000 pid=3272 execve guuid=c89c35dc-1800-0000-6c50-3137c90c0000 pid=3273 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c89c35dc-1800-0000-6c50-3137c90c0000 pid=3273 execve guuid=ec17bbdc-1800-0000-6c50-3137ca0c0000 pid=3274 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=ec17bbdc-1800-0000-6c50-3137ca0c0000 pid=3274 execve guuid=ac0648dd-1800-0000-6c50-3137cb0c0000 pid=3275 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=ac0648dd-1800-0000-6c50-3137cb0c0000 pid=3275 execve guuid=9d91c3dd-1800-0000-6c50-3137cc0c0000 pid=3276 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=9d91c3dd-1800-0000-6c50-3137cc0c0000 pid=3276 execve guuid=96a13bde-1800-0000-6c50-3137cd0c0000 pid=3277 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=96a13bde-1800-0000-6c50-3137cd0c0000 pid=3277 execve guuid=29edc1de-1800-0000-6c50-3137ce0c0000 pid=3278 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=29edc1de-1800-0000-6c50-3137ce0c0000 pid=3278 execve guuid=bb323bdf-1800-0000-6c50-3137cf0c0000 pid=3279 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=bb323bdf-1800-0000-6c50-3137cf0c0000 pid=3279 execve guuid=c3beb3df-1800-0000-6c50-3137d00c0000 pid=3280 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c3beb3df-1800-0000-6c50-3137d00c0000 pid=3280 execve guuid=76c342e0-1800-0000-6c50-3137d10c0000 pid=3281 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=76c342e0-1800-0000-6c50-3137d10c0000 pid=3281 execve guuid=9e56f0e0-1800-0000-6c50-3137d20c0000 pid=3282 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=9e56f0e0-1800-0000-6c50-3137d20c0000 pid=3282 execve guuid=f8bea9e1-1800-0000-6c50-3137d30c0000 pid=3283 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=f8bea9e1-1800-0000-6c50-3137d30c0000 pid=3283 execve guuid=10515be2-1800-0000-6c50-3137d40c0000 pid=3284 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=10515be2-1800-0000-6c50-3137d40c0000 pid=3284 execve guuid=86ca78e3-1800-0000-6c50-3137d50c0000 pid=3285 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=86ca78e3-1800-0000-6c50-3137d50c0000 pid=3285 execve guuid=fc5349e4-1800-0000-6c50-3137d60c0000 pid=3286 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=fc5349e4-1800-0000-6c50-3137d60c0000 pid=3286 execve guuid=d8a285e5-1800-0000-6c50-3137d70c0000 pid=3287 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=d8a285e5-1800-0000-6c50-3137d70c0000 pid=3287 execve guuid=4a0f51e6-1800-0000-6c50-3137d80c0000 pid=3288 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=4a0f51e6-1800-0000-6c50-3137d80c0000 pid=3288 execve guuid=e933c4e6-1800-0000-6c50-3137d90c0000 pid=3289 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e933c4e6-1800-0000-6c50-3137d90c0000 pid=3289 execve guuid=da143ae7-1800-0000-6c50-3137da0c0000 pid=3290 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=da143ae7-1800-0000-6c50-3137da0c0000 pid=3290 execve guuid=8a04bde7-1800-0000-6c50-3137db0c0000 pid=3291 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=8a04bde7-1800-0000-6c50-3137db0c0000 pid=3291 execve guuid=c9d458e8-1800-0000-6c50-3137dc0c0000 pid=3292 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c9d458e8-1800-0000-6c50-3137dc0c0000 pid=3292 execve guuid=9dd30be9-1800-0000-6c50-3137dd0c0000 pid=3293 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=9dd30be9-1800-0000-6c50-3137dd0c0000 pid=3293 execve guuid=9278a5e9-1800-0000-6c50-3137de0c0000 pid=3294 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=9278a5e9-1800-0000-6c50-3137de0c0000 pid=3294 execve guuid=201c3aea-1800-0000-6c50-3137df0c0000 pid=3295 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=201c3aea-1800-0000-6c50-3137df0c0000 pid=3295 execve guuid=e9f8c6ea-1800-0000-6c50-3137e00c0000 pid=3296 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e9f8c6ea-1800-0000-6c50-3137e00c0000 pid=3296 execve guuid=4abf5deb-1800-0000-6c50-3137e10c0000 pid=3297 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=4abf5deb-1800-0000-6c50-3137e10c0000 pid=3297 execve guuid=074323ec-1800-0000-6c50-3137e20c0000 pid=3298 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=074323ec-1800-0000-6c50-3137e20c0000 pid=3298 execve guuid=67c000ed-1800-0000-6c50-3137e30c0000 pid=3299 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=67c000ed-1800-0000-6c50-3137e30c0000 pid=3299 execve guuid=3a47d3ed-1800-0000-6c50-3137e50c0000 pid=3301 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=3a47d3ed-1800-0000-6c50-3137e50c0000 pid=3301 execve guuid=133c76ee-1800-0000-6c50-3137e60c0000 pid=3302 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=133c76ee-1800-0000-6c50-3137e60c0000 pid=3302 execve guuid=11a1abef-1800-0000-6c50-3137e70c0000 pid=3303 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=11a1abef-1800-0000-6c50-3137e70c0000 pid=3303 execve guuid=fe462bf0-1800-0000-6c50-3137ea0c0000 pid=3306 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=fe462bf0-1800-0000-6c50-3137ea0c0000 pid=3306 execve guuid=2a36b0f0-1800-0000-6c50-3137ed0c0000 pid=3309 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2a36b0f0-1800-0000-6c50-3137ed0c0000 pid=3309 execve guuid=08c016f1-1800-0000-6c50-3137ef0c0000 pid=3311 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=08c016f1-1800-0000-6c50-3137ef0c0000 pid=3311 execve guuid=464186f1-1800-0000-6c50-3137f10c0000 pid=3313 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=464186f1-1800-0000-6c50-3137f10c0000 pid=3313 execve guuid=eba6fff1-1800-0000-6c50-3137f20c0000 pid=3314 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=eba6fff1-1800-0000-6c50-3137f20c0000 pid=3314 execve guuid=584f93f2-1800-0000-6c50-3137f40c0000 pid=3316 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=584f93f2-1800-0000-6c50-3137f40c0000 pid=3316 execve guuid=d55942f3-1800-0000-6c50-3137f50c0000 pid=3317 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=d55942f3-1800-0000-6c50-3137f50c0000 pid=3317 execve guuid=5a40e2f3-1800-0000-6c50-3137f60c0000 pid=3318 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=5a40e2f3-1800-0000-6c50-3137f60c0000 pid=3318 execve guuid=bb7366f4-1800-0000-6c50-3137f70c0000 pid=3319 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=bb7366f4-1800-0000-6c50-3137f70c0000 pid=3319 execve guuid=2dcbfbf4-1800-0000-6c50-3137f90c0000 pid=3321 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2dcbfbf4-1800-0000-6c50-3137f90c0000 pid=3321 execve guuid=c95d90f5-1800-0000-6c50-3137fc0c0000 pid=3324 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c95d90f5-1800-0000-6c50-3137fc0c0000 pid=3324 execve guuid=35fb06f6-1800-0000-6c50-3137fe0c0000 pid=3326 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=35fb06f6-1800-0000-6c50-3137fe0c0000 pid=3326 execve guuid=ce2d6ff6-1800-0000-6c50-3137000d0000 pid=3328 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=ce2d6ff6-1800-0000-6c50-3137000d0000 pid=3328 execve guuid=6f97f0f6-1800-0000-6c50-3137020d0000 pid=3330 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=6f97f0f6-1800-0000-6c50-3137020d0000 pid=3330 execve guuid=56fa6bf7-1800-0000-6c50-3137040d0000 pid=3332 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=56fa6bf7-1800-0000-6c50-3137040d0000 pid=3332 execve guuid=afa9fcf7-1800-0000-6c50-3137050d0000 pid=3333 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=afa9fcf7-1800-0000-6c50-3137050d0000 pid=3333 execve guuid=2e6179f8-1800-0000-6c50-3137060d0000 pid=3334 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2e6179f8-1800-0000-6c50-3137060d0000 pid=3334 execve guuid=e88c05f9-1800-0000-6c50-3137080d0000 pid=3336 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e88c05f9-1800-0000-6c50-3137080d0000 pid=3336 execve guuid=b6bd75f9-1800-0000-6c50-31370a0d0000 pid=3338 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=b6bd75f9-1800-0000-6c50-31370a0d0000 pid=3338 execve guuid=1f66f7f9-1800-0000-6c50-31370c0d0000 pid=3340 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=1f66f7f9-1800-0000-6c50-31370c0d0000 pid=3340 execve guuid=022d7afa-1800-0000-6c50-31370f0d0000 pid=3343 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=022d7afa-1800-0000-6c50-31370f0d0000 pid=3343 execve guuid=63f1eefa-1800-0000-6c50-3137110d0000 pid=3345 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=63f1eefa-1800-0000-6c50-3137110d0000 pid=3345 execve guuid=af9886fb-1800-0000-6c50-3137120d0000 pid=3346 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=af9886fb-1800-0000-6c50-3137120d0000 pid=3346 execve guuid=699135fc-1800-0000-6c50-3137130d0000 pid=3347 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=699135fc-1800-0000-6c50-3137130d0000 pid=3347 execve guuid=061cb2fc-1800-0000-6c50-3137140d0000 pid=3348 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=061cb2fc-1800-0000-6c50-3137140d0000 pid=3348 execve guuid=b1ee4cfd-1800-0000-6c50-3137150d0000 pid=3349 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=b1ee4cfd-1800-0000-6c50-3137150d0000 pid=3349 execve guuid=775dd0fd-1800-0000-6c50-3137160d0000 pid=3350 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=775dd0fd-1800-0000-6c50-3137160d0000 pid=3350 execve guuid=0fcb49fe-1800-0000-6c50-3137170d0000 pid=3351 /usr/bin/ls guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=0fcb49fe-1800-0000-6c50-3137170d0000 pid=3351 execve guuid=e5e0cafe-1800-0000-6c50-3137180d0000 pid=3352 /usr/bin/rm guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e5e0cafe-1800-0000-6c50-3137180d0000 pid=3352 execve guuid=d15219ff-1800-0000-6c50-3137190d0000 pid=3353 /usr/bin/wget net send-data write-file guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=d15219ff-1800-0000-6c50-3137190d0000 pid=3353 execve guuid=60c4138d-1900-0000-6c50-3137330e0000 pid=3635 /usr/bin/chmod guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=60c4138d-1900-0000-6c50-3137330e0000 pid=3635 execve guuid=7f6d508d-1900-0000-6c50-3137350e0000 pid=3637 /usr/bin/dash guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=7f6d508d-1900-0000-6c50-3137350e0000 pid=3637 clone guuid=fb7cf38d-1900-0000-6c50-3137390e0000 pid=3641 /usr/bin/rm guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=fb7cf38d-1900-0000-6c50-3137390e0000 pid=3641 execve guuid=0a90308e-1900-0000-6c50-31373a0e0000 pid=3642 /usr/bin/wget net send-data write-file guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=0a90308e-1900-0000-6c50-31373a0e0000 pid=3642 execve guuid=0b00d9e9-1900-0000-6c50-3137d20e0000 pid=3794 /usr/bin/chmod guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=0b00d9e9-1900-0000-6c50-3137d20e0000 pid=3794 execve guuid=c9882dea-1900-0000-6c50-3137d40e0000 pid=3796 /usr/bin/dash guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=c9882dea-1900-0000-6c50-3137d40e0000 pid=3796 clone guuid=8ea181ec-1900-0000-6c50-3137d80e0000 pid=3800 /usr/bin/rm guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=8ea181ec-1900-0000-6c50-3137d80e0000 pid=3800 execve guuid=2654e3ec-1900-0000-6c50-3137d90e0000 pid=3801 /usr/bin/wget net send-data write-file guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=2654e3ec-1900-0000-6c50-3137d90e0000 pid=3801 execve guuid=7602d036-1b00-0000-6c50-3137ea120000 pid=4842 /usr/bin/chmod guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=7602d036-1b00-0000-6c50-3137ea120000 pid=4842 execve guuid=e51b4537-1b00-0000-6c50-3137ec120000 pid=4844 /usr/bin/dash guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=e51b4537-1b00-0000-6c50-3137ec120000 pid=4844 clone guuid=d2d13938-1b00-0000-6c50-3137f1120000 pid=4849 /usr/bin/rm guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=d2d13938-1b00-0000-6c50-3137f1120000 pid=4849 execve guuid=84319938-1b00-0000-6c50-3137f5120000 pid=4853 /usr/bin/wget net send-data write-file guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=84319938-1b00-0000-6c50-3137f5120000 pid=4853 execve guuid=b6f84676-1b00-0000-6c50-31378f130000 pid=5007 /usr/bin/chmod guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=b6f84676-1b00-0000-6c50-31378f130000 pid=5007 execve guuid=65b68876-1b00-0000-6c50-313791130000 pid=5009 /usr/bin/dash guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=65b68876-1b00-0000-6c50-313791130000 pid=5009 clone guuid=73b61878-1b00-0000-6c50-313796130000 pid=5014 /usr/bin/rm guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=73b61878-1b00-0000-6c50-313796130000 pid=5014 execve guuid=5dcb5978-1b00-0000-6c50-313798130000 pid=5016 /usr/bin/wget net send-data write-file guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=5dcb5978-1b00-0000-6c50-313798130000 pid=5016 execve guuid=0c0776e9-1b00-0000-6c50-3137ea140000 pid=5354 /usr/bin/chmod guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=0c0776e9-1b00-0000-6c50-3137ea140000 pid=5354 execve guuid=7b5eade9-1b00-0000-6c50-3137eb140000 pid=5355 /usr/bin/dash guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=7b5eade9-1b00-0000-6c50-3137eb140000 pid=5355 clone guuid=847738ea-1b00-0000-6c50-3137ed140000 pid=5357 /usr/bin/rm delete-file guuid=c110c1b7-1800-0000-6c50-3137670c0000 pid=3175->guuid=847738ea-1b00-0000-6c50-3137ed140000 pid=5357 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=d15219ff-1800-0000-6c50-3137190d0000 pid=3353->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=0a90308e-1900-0000-6c50-31373a0e0000 pid=3642->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=2654e3ec-1900-0000-6c50-3137d90e0000 pid=3801->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=84319938-1b00-0000-6c50-3137f5120000 pid=4853->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=5dcb5978-1b00-0000-6c50-313798130000 pid=5016->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-07 13:53:29 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ecb432b0f7344e66dbdb68d21819284264db3707941f0c8ea95db0abcb26e595

(this sample)

  
Delivery method
Distributed via web download

Comments