MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f6dd217d20a907a6cbb9998c50f28e3bbf6154d3457fd39c00ce324f37140714. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: f6dd217d20a907a6cbb9998c50f28e3bbf6154d3457fd39c00ce324f37140714
SHA3-384 hash: 167ce94f00dc873ec87663ff4fcacb769a3e0e70fabe72d6e694f01e9a5863acff03cdeb55f8defb9346e23c59aaee8a
SHA1 hash: 70683a490d6b7ca4d08a8ec2c93ae377f059bbe7
MD5 hash: c94217555cc96641720ef3960daef32f
humanhash: hotel-kentucky-connecticut-march
File name:lil
Download: download sample
File size:847 bytes
First seen:2026-06-10 07:56:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkaPfIjvI6APx8IxqX1EaSIYPBCy7SIk+X:kXCKysE2hi0ziQvZohaPfKheqX21n+UX
TLSH T1F001AFDEC005866055D6D86C36976088B811C3CF2A418FB9BF9C543DCBECE287019F85
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/Wz7tn/an/aelf ua-wget
http://188.132.232.81/mSPNn/an/aelf ua-wget
http://188.132.232.81/MFln/an/aelf ua-wget
http://188.132.232.81/jRren/an/aelf ua-wget
http://188.132.232.81/0BD3n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=cbe5b622-1700-0000-e724-d12d500e0000 pid=3664 /usr/bin/sudo guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672 /tmp/sample.bin write-file guuid=cbe5b622-1700-0000-e724-d12d500e0000 pid=3664->guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672 execve guuid=e7329324-1700-0000-e724-d12d590e0000 pid=3673 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=e7329324-1700-0000-e724-d12d590e0000 pid=3673 execve guuid=84a5f024-1700-0000-e724-d12d5d0e0000 pid=3677 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=84a5f024-1700-0000-e724-d12d5d0e0000 pid=3677 execve guuid=aa3e4825-1700-0000-e724-d12d600e0000 pid=3680 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=aa3e4825-1700-0000-e724-d12d600e0000 pid=3680 execve guuid=a5769f25-1700-0000-e724-d12d620e0000 pid=3682 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=a5769f25-1700-0000-e724-d12d620e0000 pid=3682 execve guuid=31b0f925-1700-0000-e724-d12d640e0000 pid=3684 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=31b0f925-1700-0000-e724-d12d640e0000 pid=3684 execve guuid=bb0e5526-1700-0000-e724-d12d670e0000 pid=3687 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=bb0e5526-1700-0000-e724-d12d670e0000 pid=3687 execve guuid=40cbb126-1700-0000-e724-d12d690e0000 pid=3689 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=40cbb126-1700-0000-e724-d12d690e0000 pid=3689 execve guuid=53650727-1700-0000-e724-d12d6b0e0000 pid=3691 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=53650727-1700-0000-e724-d12d6b0e0000 pid=3691 execve guuid=c04c6727-1700-0000-e724-d12d6d0e0000 pid=3693 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c04c6727-1700-0000-e724-d12d6d0e0000 pid=3693 execve guuid=0d51c727-1700-0000-e724-d12d6f0e0000 pid=3695 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=0d51c727-1700-0000-e724-d12d6f0e0000 pid=3695 execve guuid=8bc32428-1700-0000-e724-d12d720e0000 pid=3698 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=8bc32428-1700-0000-e724-d12d720e0000 pid=3698 execve guuid=11a28028-1700-0000-e724-d12d740e0000 pid=3700 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=11a28028-1700-0000-e724-d12d740e0000 pid=3700 execve guuid=3017d728-1700-0000-e724-d12d780e0000 pid=3704 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=3017d728-1700-0000-e724-d12d780e0000 pid=3704 execve guuid=96124929-1700-0000-e724-d12d7a0e0000 pid=3706 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=96124929-1700-0000-e724-d12d7a0e0000 pid=3706 execve guuid=7cda102a-1700-0000-e724-d12d810e0000 pid=3713 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=7cda102a-1700-0000-e724-d12d810e0000 pid=3713 execve guuid=c46f682a-1700-0000-e724-d12d850e0000 pid=3717 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c46f682a-1700-0000-e724-d12d850e0000 pid=3717 execve guuid=4cefba2a-1700-0000-e724-d12d860e0000 pid=3718 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=4cefba2a-1700-0000-e724-d12d860e0000 pid=3718 execve guuid=33160e2b-1700-0000-e724-d12d870e0000 pid=3719 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=33160e2b-1700-0000-e724-d12d870e0000 pid=3719 execve guuid=99e0642b-1700-0000-e724-d12d8b0e0000 pid=3723 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=99e0642b-1700-0000-e724-d12d8b0e0000 pid=3723 execve guuid=695bc82b-1700-0000-e724-d12d8c0e0000 pid=3724 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=695bc82b-1700-0000-e724-d12d8c0e0000 pid=3724 execve guuid=43aa2e2c-1700-0000-e724-d12d8e0e0000 pid=3726 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=43aa2e2c-1700-0000-e724-d12d8e0e0000 pid=3726 execve guuid=6bcb892c-1700-0000-e724-d12d900e0000 pid=3728 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=6bcb892c-1700-0000-e724-d12d900e0000 pid=3728 execve guuid=2e89fb2c-1700-0000-e724-d12d940e0000 pid=3732 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2e89fb2c-1700-0000-e724-d12d940e0000 pid=3732 execve guuid=80ec522d-1700-0000-e724-d12d980e0000 pid=3736 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=80ec522d-1700-0000-e724-d12d980e0000 pid=3736 execve guuid=5a0bb12d-1700-0000-e724-d12d9a0e0000 pid=3738 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=5a0bb12d-1700-0000-e724-d12d9a0e0000 pid=3738 execve guuid=ceb8262e-1700-0000-e724-d12d9f0e0000 pid=3743 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ceb8262e-1700-0000-e724-d12d9f0e0000 pid=3743 execve guuid=e469822e-1700-0000-e724-d12da20e0000 pid=3746 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=e469822e-1700-0000-e724-d12da20e0000 pid=3746 execve guuid=a5eb672f-1700-0000-e724-d12da60e0000 pid=3750 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=a5eb672f-1700-0000-e724-d12da60e0000 pid=3750 execve guuid=84e0c12f-1700-0000-e724-d12daa0e0000 pid=3754 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=84e0c12f-1700-0000-e724-d12daa0e0000 pid=3754 execve guuid=6b511b30-1700-0000-e724-d12dae0e0000 pid=3758 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=6b511b30-1700-0000-e724-d12dae0e0000 pid=3758 execve guuid=7e7a7230-1700-0000-e724-d12db00e0000 pid=3760 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=7e7a7230-1700-0000-e724-d12db00e0000 pid=3760 execve guuid=f20ecc30-1700-0000-e724-d12db20e0000 pid=3762 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f20ecc30-1700-0000-e724-d12db20e0000 pid=3762 execve guuid=3af72e31-1700-0000-e724-d12db60e0000 pid=3766 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=3af72e31-1700-0000-e724-d12db60e0000 pid=3766 execve guuid=bace8531-1700-0000-e724-d12dba0e0000 pid=3770 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=bace8531-1700-0000-e724-d12dba0e0000 pid=3770 execve guuid=2ef9db31-1700-0000-e724-d12dbc0e0000 pid=3772 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2ef9db31-1700-0000-e724-d12dbc0e0000 pid=3772 execve guuid=418b3932-1700-0000-e724-d12dbf0e0000 pid=3775 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=418b3932-1700-0000-e724-d12dbf0e0000 pid=3775 execve guuid=27929d32-1700-0000-e724-d12dc10e0000 pid=3777 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=27929d32-1700-0000-e724-d12dc10e0000 pid=3777 execve guuid=4fb7fd32-1700-0000-e724-d12dc30e0000 pid=3779 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=4fb7fd32-1700-0000-e724-d12dc30e0000 pid=3779 execve guuid=ed1a5933-1700-0000-e724-d12dc50e0000 pid=3781 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ed1a5933-1700-0000-e724-d12dc50e0000 pid=3781 execve guuid=24eeb233-1700-0000-e724-d12dc80e0000 pid=3784 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=24eeb233-1700-0000-e724-d12dc80e0000 pid=3784 execve guuid=4fec1f34-1700-0000-e724-d12dca0e0000 pid=3786 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=4fec1f34-1700-0000-e724-d12dca0e0000 pid=3786 execve guuid=81718434-1700-0000-e724-d12dcc0e0000 pid=3788 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=81718434-1700-0000-e724-d12dcc0e0000 pid=3788 execve guuid=f48de834-1700-0000-e724-d12dce0e0000 pid=3790 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f48de834-1700-0000-e724-d12dce0e0000 pid=3790 execve guuid=11ed4835-1700-0000-e724-d12dd10e0000 pid=3793 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=11ed4835-1700-0000-e724-d12dd10e0000 pid=3793 execve guuid=c110a835-1700-0000-e724-d12dd30e0000 pid=3795 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c110a835-1700-0000-e724-d12dd30e0000 pid=3795 execve guuid=a5b10436-1700-0000-e724-d12dd50e0000 pid=3797 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=a5b10436-1700-0000-e724-d12dd50e0000 pid=3797 execve guuid=c08f6436-1700-0000-e724-d12dd70e0000 pid=3799 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c08f6436-1700-0000-e724-d12dd70e0000 pid=3799 execve guuid=1112c736-1700-0000-e724-d12dda0e0000 pid=3802 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=1112c736-1700-0000-e724-d12dda0e0000 pid=3802 execve guuid=5d1e2737-1700-0000-e724-d12ddc0e0000 pid=3804 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=5d1e2737-1700-0000-e724-d12ddc0e0000 pid=3804 execve guuid=64bc7e37-1700-0000-e724-d12dde0e0000 pid=3806 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=64bc7e37-1700-0000-e724-d12dde0e0000 pid=3806 execve guuid=2203d237-1700-0000-e724-d12de00e0000 pid=3808 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2203d237-1700-0000-e724-d12de00e0000 pid=3808 execve guuid=b1dc2938-1700-0000-e724-d12de30e0000 pid=3811 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=b1dc2938-1700-0000-e724-d12de30e0000 pid=3811 execve guuid=502f8338-1700-0000-e724-d12de50e0000 pid=3813 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=502f8338-1700-0000-e724-d12de50e0000 pid=3813 execve guuid=44c4d938-1700-0000-e724-d12de80e0000 pid=3816 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=44c4d938-1700-0000-e724-d12de80e0000 pid=3816 execve guuid=816f2239-1700-0000-e724-d12deb0e0000 pid=3819 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=816f2239-1700-0000-e724-d12deb0e0000 pid=3819 execve guuid=98867c39-1700-0000-e724-d12df00e0000 pid=3824 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=98867c39-1700-0000-e724-d12df00e0000 pid=3824 execve guuid=bacbdd39-1700-0000-e724-d12df40e0000 pid=3828 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=bacbdd39-1700-0000-e724-d12df40e0000 pid=3828 execve guuid=c9df7c3a-1700-0000-e724-d12df70e0000 pid=3831 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c9df7c3a-1700-0000-e724-d12df70e0000 pid=3831 execve guuid=af64e43a-1700-0000-e724-d12dfa0e0000 pid=3834 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=af64e43a-1700-0000-e724-d12dfa0e0000 pid=3834 execve guuid=f183473b-1700-0000-e724-d12dfd0e0000 pid=3837 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f183473b-1700-0000-e724-d12dfd0e0000 pid=3837 execve guuid=b0b9ba3b-1700-0000-e724-d12d000f0000 pid=3840 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=b0b9ba3b-1700-0000-e724-d12d000f0000 pid=3840 execve guuid=00ef283c-1700-0000-e724-d12d030f0000 pid=3843 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=00ef283c-1700-0000-e724-d12d030f0000 pid=3843 execve guuid=f17c873c-1700-0000-e724-d12d060f0000 pid=3846 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f17c873c-1700-0000-e724-d12d060f0000 pid=3846 execve guuid=42dce63c-1700-0000-e724-d12d0a0f0000 pid=3850 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=42dce63c-1700-0000-e724-d12d0a0f0000 pid=3850 execve guuid=ea61513d-1700-0000-e724-d12d0e0f0000 pid=3854 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ea61513d-1700-0000-e724-d12d0e0f0000 pid=3854 execve guuid=579dac3d-1700-0000-e724-d12d110f0000 pid=3857 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=579dac3d-1700-0000-e724-d12d110f0000 pid=3857 execve guuid=e2fa083e-1700-0000-e724-d12d140f0000 pid=3860 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=e2fa083e-1700-0000-e724-d12d140f0000 pid=3860 execve guuid=6214633e-1700-0000-e724-d12d180f0000 pid=3864 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=6214633e-1700-0000-e724-d12d180f0000 pid=3864 execve guuid=39c5c13e-1700-0000-e724-d12d1c0f0000 pid=3868 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=39c5c13e-1700-0000-e724-d12d1c0f0000 pid=3868 execve guuid=5459213f-1700-0000-e724-d12d1f0f0000 pid=3871 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=5459213f-1700-0000-e724-d12d1f0f0000 pid=3871 execve guuid=f065833f-1700-0000-e724-d12d220f0000 pid=3874 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f065833f-1700-0000-e724-d12d220f0000 pid=3874 execve guuid=18e7df3f-1700-0000-e724-d12d250f0000 pid=3877 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=18e7df3f-1700-0000-e724-d12d250f0000 pid=3877 execve guuid=1a464240-1700-0000-e724-d12d270f0000 pid=3879 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=1a464240-1700-0000-e724-d12d270f0000 pid=3879 execve guuid=1e0d9f40-1700-0000-e724-d12d2f0f0000 pid=3887 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=1e0d9f40-1700-0000-e724-d12d2f0f0000 pid=3887 execve guuid=ea3ff340-1700-0000-e724-d12d300f0000 pid=3888 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ea3ff340-1700-0000-e724-d12d300f0000 pid=3888 execve guuid=afa65741-1700-0000-e724-d12d310f0000 pid=3889 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=afa65741-1700-0000-e724-d12d310f0000 pid=3889 execve guuid=f9aeb641-1700-0000-e724-d12d340f0000 pid=3892 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f9aeb641-1700-0000-e724-d12d340f0000 pid=3892 execve guuid=4d261742-1700-0000-e724-d12d360f0000 pid=3894 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=4d261742-1700-0000-e724-d12d360f0000 pid=3894 execve guuid=2d3f7942-1700-0000-e724-d12d380f0000 pid=3896 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2d3f7942-1700-0000-e724-d12d380f0000 pid=3896 execve guuid=a1d6e042-1700-0000-e724-d12d3b0f0000 pid=3899 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=a1d6e042-1700-0000-e724-d12d3b0f0000 pid=3899 execve guuid=de3f5143-1700-0000-e724-d12d3e0f0000 pid=3902 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=de3f5143-1700-0000-e724-d12d3e0f0000 pid=3902 execve guuid=71c9b643-1700-0000-e724-d12d400f0000 pid=3904 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=71c9b643-1700-0000-e724-d12d400f0000 pid=3904 execve guuid=4c871244-1700-0000-e724-d12d440f0000 pid=3908 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=4c871244-1700-0000-e724-d12d440f0000 pid=3908 execve guuid=79dc6844-1700-0000-e724-d12d450f0000 pid=3909 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=79dc6844-1700-0000-e724-d12d450f0000 pid=3909 execve guuid=185ec244-1700-0000-e724-d12d490f0000 pid=3913 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=185ec244-1700-0000-e724-d12d490f0000 pid=3913 execve guuid=b0791945-1700-0000-e724-d12d4d0f0000 pid=3917 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=b0791945-1700-0000-e724-d12d4d0f0000 pid=3917 execve guuid=94c37645-1700-0000-e724-d12d4f0f0000 pid=3919 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=94c37645-1700-0000-e724-d12d4f0f0000 pid=3919 execve guuid=05b7d045-1700-0000-e724-d12d520f0000 pid=3922 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=05b7d045-1700-0000-e724-d12d520f0000 pid=3922 execve guuid=6ea82b46-1700-0000-e724-d12d560f0000 pid=3926 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=6ea82b46-1700-0000-e724-d12d560f0000 pid=3926 execve guuid=1a767c46-1700-0000-e724-d12d580f0000 pid=3928 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=1a767c46-1700-0000-e724-d12d580f0000 pid=3928 execve guuid=2cc2d446-1700-0000-e724-d12d5b0f0000 pid=3931 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2cc2d446-1700-0000-e724-d12d5b0f0000 pid=3931 execve guuid=26be2847-1700-0000-e724-d12d5d0f0000 pid=3933 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=26be2847-1700-0000-e724-d12d5d0f0000 pid=3933 execve guuid=fcbb7c47-1700-0000-e724-d12d600f0000 pid=3936 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=fcbb7c47-1700-0000-e724-d12d600f0000 pid=3936 execve guuid=f565d247-1700-0000-e724-d12d620f0000 pid=3938 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f565d247-1700-0000-e724-d12d620f0000 pid=3938 execve guuid=ea8b2548-1700-0000-e724-d12d640f0000 pid=3940 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ea8b2548-1700-0000-e724-d12d640f0000 pid=3940 execve guuid=de177d48-1700-0000-e724-d12d680f0000 pid=3944 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=de177d48-1700-0000-e724-d12d680f0000 pid=3944 execve guuid=9c2cdd48-1700-0000-e724-d12d6c0f0000 pid=3948 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=9c2cdd48-1700-0000-e724-d12d6c0f0000 pid=3948 execve guuid=ba954249-1700-0000-e724-d12d6d0f0000 pid=3949 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ba954249-1700-0000-e724-d12d6d0f0000 pid=3949 execve guuid=9ed89e49-1700-0000-e724-d12d700f0000 pid=3952 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=9ed89e49-1700-0000-e724-d12d700f0000 pid=3952 execve guuid=2c2bfa49-1700-0000-e724-d12d720f0000 pid=3954 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2c2bfa49-1700-0000-e724-d12d720f0000 pid=3954 execve guuid=f751524a-1700-0000-e724-d12d750f0000 pid=3957 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f751524a-1700-0000-e724-d12d750f0000 pid=3957 execve guuid=0bddae4a-1700-0000-e724-d12d770f0000 pid=3959 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=0bddae4a-1700-0000-e724-d12d770f0000 pid=3959 execve guuid=3e910b4b-1700-0000-e724-d12d7a0f0000 pid=3962 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=3e910b4b-1700-0000-e724-d12d7a0f0000 pid=3962 execve guuid=6004854b-1700-0000-e724-d12d7e0f0000 pid=3966 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=6004854b-1700-0000-e724-d12d7e0f0000 pid=3966 execve guuid=3f04fa4b-1700-0000-e724-d12d820f0000 pid=3970 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=3f04fa4b-1700-0000-e724-d12d820f0000 pid=3970 execve guuid=82c96c4c-1700-0000-e724-d12d840f0000 pid=3972 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=82c96c4c-1700-0000-e724-d12d840f0000 pid=3972 execve guuid=cc31db4c-1700-0000-e724-d12d890f0000 pid=3977 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=cc31db4c-1700-0000-e724-d12d890f0000 pid=3977 execve guuid=daa95d4d-1700-0000-e724-d12d8a0f0000 pid=3978 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=daa95d4d-1700-0000-e724-d12d8a0f0000 pid=3978 execve guuid=ba2cc04d-1700-0000-e724-d12d8e0f0000 pid=3982 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ba2cc04d-1700-0000-e724-d12d8e0f0000 pid=3982 execve guuid=d7fe174e-1700-0000-e724-d12d900f0000 pid=3984 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=d7fe174e-1700-0000-e724-d12d900f0000 pid=3984 execve guuid=6df1684e-1700-0000-e724-d12d930f0000 pid=3987 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=6df1684e-1700-0000-e724-d12d930f0000 pid=3987 execve guuid=2403bf4e-1700-0000-e724-d12d950f0000 pid=3989 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2403bf4e-1700-0000-e724-d12d950f0000 pid=3989 execve guuid=5f90104f-1700-0000-e724-d12d970f0000 pid=3991 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=5f90104f-1700-0000-e724-d12d970f0000 pid=3991 execve guuid=8cbe694f-1700-0000-e724-d12d990f0000 pid=3993 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=8cbe694f-1700-0000-e724-d12d990f0000 pid=3993 execve guuid=78a6c44f-1700-0000-e724-d12d9d0f0000 pid=3997 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=78a6c44f-1700-0000-e724-d12d9d0f0000 pid=3997 execve guuid=d0d42550-1700-0000-e724-d12da10f0000 pid=4001 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=d0d42550-1700-0000-e724-d12da10f0000 pid=4001 execve guuid=2fc97b50-1700-0000-e724-d12da30f0000 pid=4003 /usr/bin/ls guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2fc97b50-1700-0000-e724-d12da30f0000 pid=4003 execve guuid=eb73d550-1700-0000-e724-d12da80f0000 pid=4008 /usr/bin/rm guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=eb73d550-1700-0000-e724-d12da80f0000 pid=4008 execve guuid=eca70951-1700-0000-e724-d12da90f0000 pid=4009 /usr/bin/wget net send-data write-file guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=eca70951-1700-0000-e724-d12da90f0000 pid=4009 execve guuid=309d4094-1700-0000-e724-d12d54100000 pid=4180 /usr/bin/chmod guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=309d4094-1700-0000-e724-d12d54100000 pid=4180 execve guuid=c06eb094-1700-0000-e724-d12d55100000 pid=4181 /tmp/Wz7t guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c06eb094-1700-0000-e724-d12d55100000 pid=4181 execve guuid=dfec1896-1700-0000-e724-d12d57100000 pid=4183 /usr/bin/rm guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=dfec1896-1700-0000-e724-d12d57100000 pid=4183 execve guuid=196c6a96-1700-0000-e724-d12d58100000 pid=4184 /usr/bin/wget net send-data write-file guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=196c6a96-1700-0000-e724-d12d58100000 pid=4184 execve guuid=ca5a0dba-1700-0000-e724-d12dbd100000 pid=4285 /usr/bin/chmod guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ca5a0dba-1700-0000-e724-d12dbd100000 pid=4285 execve guuid=2afd72ba-1700-0000-e724-d12dbe100000 pid=4286 /tmp/mSPN guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=2afd72ba-1700-0000-e724-d12dbe100000 pid=4286 execve guuid=79f268bb-1700-0000-e724-d12dc3100000 pid=4291 /usr/bin/rm guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=79f268bb-1700-0000-e724-d12dc3100000 pid=4291 execve guuid=b95eadbb-1700-0000-e724-d12dc4100000 pid=4292 /usr/bin/wget net send-data write-file guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=b95eadbb-1700-0000-e724-d12dc4100000 pid=4292 execve guuid=ab06cac1-1700-0000-e724-d12dda100000 pid=4314 /usr/bin/chmod guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=ab06cac1-1700-0000-e724-d12dda100000 pid=4314 execve guuid=85e834c2-1700-0000-e724-d12ddc100000 pid=4316 /tmp/MFl guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=85e834c2-1700-0000-e724-d12ddc100000 pid=4316 execve guuid=be832bc4-1700-0000-e724-d12de4100000 pid=4324 /usr/bin/rm guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=be832bc4-1700-0000-e724-d12de4100000 pid=4324 execve guuid=873066c4-1700-0000-e724-d12de5100000 pid=4325 /usr/bin/wget net send-data write-file guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=873066c4-1700-0000-e724-d12de5100000 pid=4325 execve guuid=7eb49aca-1700-0000-e724-d12dfc100000 pid=4348 /usr/bin/chmod guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=7eb49aca-1700-0000-e724-d12dfc100000 pid=4348 execve guuid=7bd2eaca-1700-0000-e724-d12d00110000 pid=4352 /tmp/jRre guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=7bd2eaca-1700-0000-e724-d12d00110000 pid=4352 execve guuid=0f279ecb-1700-0000-e724-d12d04110000 pid=4356 /usr/bin/rm guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=0f279ecb-1700-0000-e724-d12d04110000 pid=4356 execve guuid=7a7fd1cb-1700-0000-e724-d12d07110000 pid=4359 /usr/bin/wget net send-data write-file guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=7a7fd1cb-1700-0000-e724-d12d07110000 pid=4359 execve guuid=678b18d2-1700-0000-e724-d12d26110000 pid=4390 /usr/bin/chmod guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=678b18d2-1700-0000-e724-d12d26110000 pid=4390 execve guuid=c46065d2-1700-0000-e724-d12d2a110000 pid=4394 /tmp/0BD3 guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=c46065d2-1700-0000-e724-d12d2a110000 pid=4394 execve guuid=f7035dd3-1700-0000-e724-d12d31110000 pid=4401 /usr/bin/rm delete-file guuid=f3a05c24-1700-0000-e724-d12d580e0000 pid=3672->guuid=f7035dd3-1700-0000-e724-d12d31110000 pid=4401 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=eca70951-1700-0000-e724-d12da90f0000 pid=4009->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=196c6a96-1700-0000-e724-d12d58100000 pid=4184->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=b95eadbb-1700-0000-e724-d12dc4100000 pid=4292->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=873066c4-1700-0000-e724-d12de5100000 pid=4325->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=7a7fd1cb-1700-0000-e724-d12d07110000 pid=4359->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-10 07:57:44 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f6dd217d20a907a6cbb9998c50f28e3bbf6154d3457fd39c00ce324f37140714

(this sample)

  
Delivery method
Distributed via web download

Comments