MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7d98e451b7acb40adea1b84e5df78431e8bf128a7d48dcb5222e4150dd2e805. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f7d98e451b7acb40adea1b84e5df78431e8bf128a7d48dcb5222e4150dd2e805
SHA3-384 hash: 0cdac172705f63c81afaa51df8b2bdbb930687b7b4719681ff9932defacccf3fb000cbeb6cf333a656a3c7e816ba1735
SHA1 hash: d5a50ce7fd9bac71baffc5c1ac442a2d9e67c500
MD5 hash: 44b0e909b120864de8bfe579cb97e265
humanhash: avocado-tango-lima-princess
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-02 08:07:12 UTC
Last seen:2026-06-02 21:04:36 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkahIX6sZIakpThvIFk01ICW/Xk1Iit9uNaa:kXCKysE2hi0ziQvZohah8644GDWM1o7
TLSH T194016FDAC001DB508186F85E739756947821C3CF19414BA47E9C043D9BBD658B116FC8
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/Xd1on/an/aelf ua-wget
http://188.132.232.81/j9E4n/an/aelf ua-wget
http://188.132.232.81/jAAn/an/aelf ua-wget
http://188.132.232.81/FwWDn/an/aelf ua-wget
http://188.132.232.81/rVyn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-02T05:19:00Z UTC
Last seen:
2026-06-02T09:15:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=52fe8821-1700-0000-dcc6-6e79890d0000 pid=3465 /usr/bin/sudo guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473 /tmp/sample.bin write-file guuid=52fe8821-1700-0000-dcc6-6e79890d0000 pid=3465->guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473 execve guuid=56c15a24-1700-0000-dcc6-6e79930d0000 pid=3475 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=56c15a24-1700-0000-dcc6-6e79930d0000 pid=3475 execve guuid=79cae024-1700-0000-dcc6-6e79960d0000 pid=3478 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=79cae024-1700-0000-dcc6-6e79960d0000 pid=3478 execve guuid=eca05a25-1700-0000-dcc6-6e79980d0000 pid=3480 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=eca05a25-1700-0000-dcc6-6e79980d0000 pid=3480 execve guuid=421ed425-1700-0000-dcc6-6e799b0d0000 pid=3483 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=421ed425-1700-0000-dcc6-6e799b0d0000 pid=3483 execve guuid=08614826-1700-0000-dcc6-6e799d0d0000 pid=3485 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=08614826-1700-0000-dcc6-6e799d0d0000 pid=3485 execve guuid=3c37cf26-1700-0000-dcc6-6e79a30d0000 pid=3491 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=3c37cf26-1700-0000-dcc6-6e79a30d0000 pid=3491 execve guuid=b6594e27-1700-0000-dcc6-6e79a40d0000 pid=3492 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=b6594e27-1700-0000-dcc6-6e79a40d0000 pid=3492 execve guuid=1f08d527-1700-0000-dcc6-6e79a50d0000 pid=3493 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=1f08d527-1700-0000-dcc6-6e79a50d0000 pid=3493 execve guuid=2d106028-1700-0000-dcc6-6e79a60d0000 pid=3494 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=2d106028-1700-0000-dcc6-6e79a60d0000 pid=3494 execve guuid=6c70e728-1700-0000-dcc6-6e79a70d0000 pid=3495 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=6c70e728-1700-0000-dcc6-6e79a70d0000 pid=3495 execve guuid=8cff7229-1700-0000-dcc6-6e79a80d0000 pid=3496 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=8cff7229-1700-0000-dcc6-6e79a80d0000 pid=3496 execve guuid=51aa062a-1700-0000-dcc6-6e79a90d0000 pid=3497 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=51aa062a-1700-0000-dcc6-6e79a90d0000 pid=3497 execve guuid=54318c2a-1700-0000-dcc6-6e79aa0d0000 pid=3498 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=54318c2a-1700-0000-dcc6-6e79aa0d0000 pid=3498 execve guuid=d09d152b-1700-0000-dcc6-6e79ab0d0000 pid=3499 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d09d152b-1700-0000-dcc6-6e79ab0d0000 pid=3499 execve guuid=d8159d2b-1700-0000-dcc6-6e79ac0d0000 pid=3500 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d8159d2b-1700-0000-dcc6-6e79ac0d0000 pid=3500 execve guuid=cf2d232c-1700-0000-dcc6-6e79ad0d0000 pid=3501 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=cf2d232c-1700-0000-dcc6-6e79ad0d0000 pid=3501 execve guuid=5db7a52c-1700-0000-dcc6-6e79ae0d0000 pid=3502 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=5db7a52c-1700-0000-dcc6-6e79ae0d0000 pid=3502 execve guuid=fedb262d-1700-0000-dcc6-6e79af0d0000 pid=3503 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=fedb262d-1700-0000-dcc6-6e79af0d0000 pid=3503 execve guuid=5bec9c2d-1700-0000-dcc6-6e79b00d0000 pid=3504 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=5bec9c2d-1700-0000-dcc6-6e79b00d0000 pid=3504 execve guuid=1f48132e-1700-0000-dcc6-6e79b10d0000 pid=3505 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=1f48132e-1700-0000-dcc6-6e79b10d0000 pid=3505 execve guuid=d18e932e-1700-0000-dcc6-6e79b50d0000 pid=3509 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d18e932e-1700-0000-dcc6-6e79b50d0000 pid=3509 execve guuid=9a3afb2e-1700-0000-dcc6-6e79b60d0000 pid=3510 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=9a3afb2e-1700-0000-dcc6-6e79b60d0000 pid=3510 execve guuid=7211592f-1700-0000-dcc6-6e79b80d0000 pid=3512 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=7211592f-1700-0000-dcc6-6e79b80d0000 pid=3512 execve guuid=d1bbc82f-1700-0000-dcc6-6e79bb0d0000 pid=3515 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d1bbc82f-1700-0000-dcc6-6e79bb0d0000 pid=3515 execve guuid=b4f53730-1700-0000-dcc6-6e79be0d0000 pid=3518 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=b4f53730-1700-0000-dcc6-6e79be0d0000 pid=3518 execve guuid=06b5a530-1700-0000-dcc6-6e79c10d0000 pid=3521 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=06b5a530-1700-0000-dcc6-6e79c10d0000 pid=3521 execve guuid=dd781731-1700-0000-dcc6-6e79c30d0000 pid=3523 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=dd781731-1700-0000-dcc6-6e79c30d0000 pid=3523 execve guuid=f1497931-1700-0000-dcc6-6e79c60d0000 pid=3526 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f1497931-1700-0000-dcc6-6e79c60d0000 pid=3526 execve guuid=eb6ce031-1700-0000-dcc6-6e79c70d0000 pid=3527 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=eb6ce031-1700-0000-dcc6-6e79c70d0000 pid=3527 execve guuid=ebfd4932-1700-0000-dcc6-6e79c90d0000 pid=3529 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=ebfd4932-1700-0000-dcc6-6e79c90d0000 pid=3529 execve guuid=a22eac32-1700-0000-dcc6-6e79ca0d0000 pid=3530 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=a22eac32-1700-0000-dcc6-6e79ca0d0000 pid=3530 execve guuid=d9121033-1700-0000-dcc6-6e79cc0d0000 pid=3532 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d9121033-1700-0000-dcc6-6e79cc0d0000 pid=3532 execve guuid=6bee8433-1700-0000-dcc6-6e79cf0d0000 pid=3535 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=6bee8433-1700-0000-dcc6-6e79cf0d0000 pid=3535 execve guuid=9001d933-1700-0000-dcc6-6e79d10d0000 pid=3537 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=9001d933-1700-0000-dcc6-6e79d10d0000 pid=3537 execve guuid=d4732c34-1700-0000-dcc6-6e79d40d0000 pid=3540 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d4732c34-1700-0000-dcc6-6e79d40d0000 pid=3540 execve guuid=e6ec9d34-1700-0000-dcc6-6e79d50d0000 pid=3541 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e6ec9d34-1700-0000-dcc6-6e79d50d0000 pid=3541 execve guuid=a7dffa34-1700-0000-dcc6-6e79d70d0000 pid=3543 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=a7dffa34-1700-0000-dcc6-6e79d70d0000 pid=3543 execve guuid=fe085635-1700-0000-dcc6-6e79d90d0000 pid=3545 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=fe085635-1700-0000-dcc6-6e79d90d0000 pid=3545 execve guuid=ecdcb035-1700-0000-dcc6-6e79dc0d0000 pid=3548 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=ecdcb035-1700-0000-dcc6-6e79dc0d0000 pid=3548 execve guuid=12290a36-1700-0000-dcc6-6e79de0d0000 pid=3550 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=12290a36-1700-0000-dcc6-6e79de0d0000 pid=3550 execve guuid=befb6136-1700-0000-dcc6-6e79e10d0000 pid=3553 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=befb6136-1700-0000-dcc6-6e79e10d0000 pid=3553 execve guuid=aba8c036-1700-0000-dcc6-6e79e30d0000 pid=3555 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=aba8c036-1700-0000-dcc6-6e79e30d0000 pid=3555 execve guuid=000a2137-1700-0000-dcc6-6e79e50d0000 pid=3557 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=000a2137-1700-0000-dcc6-6e79e50d0000 pid=3557 execve guuid=52d08737-1700-0000-dcc6-6e79e80d0000 pid=3560 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=52d08737-1700-0000-dcc6-6e79e80d0000 pid=3560 execve guuid=f7d9f237-1700-0000-dcc6-6e79ea0d0000 pid=3562 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f7d9f237-1700-0000-dcc6-6e79ea0d0000 pid=3562 execve guuid=f75a5138-1700-0000-dcc6-6e79ed0d0000 pid=3565 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f75a5138-1700-0000-dcc6-6e79ed0d0000 pid=3565 execve guuid=545eba38-1700-0000-dcc6-6e79ef0d0000 pid=3567 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=545eba38-1700-0000-dcc6-6e79ef0d0000 pid=3567 execve guuid=8ee12439-1700-0000-dcc6-6e79f10d0000 pid=3569 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=8ee12439-1700-0000-dcc6-6e79f10d0000 pid=3569 execve guuid=2c388f39-1700-0000-dcc6-6e79f30d0000 pid=3571 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=2c388f39-1700-0000-dcc6-6e79f30d0000 pid=3571 execve guuid=2cfffe39-1700-0000-dcc6-6e79f40d0000 pid=3572 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=2cfffe39-1700-0000-dcc6-6e79f40d0000 pid=3572 execve guuid=46c3653a-1700-0000-dcc6-6e79f60d0000 pid=3574 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=46c3653a-1700-0000-dcc6-6e79f60d0000 pid=3574 execve guuid=f06e153b-1700-0000-dcc6-6e79f80d0000 pid=3576 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f06e153b-1700-0000-dcc6-6e79f80d0000 pid=3576 execve guuid=595e7e3b-1700-0000-dcc6-6e79fa0d0000 pid=3578 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=595e7e3b-1700-0000-dcc6-6e79fa0d0000 pid=3578 execve guuid=6ef1e63b-1700-0000-dcc6-6e79fc0d0000 pid=3580 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=6ef1e63b-1700-0000-dcc6-6e79fc0d0000 pid=3580 execve guuid=d220383c-1700-0000-dcc6-6e79fe0d0000 pid=3582 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d220383c-1700-0000-dcc6-6e79fe0d0000 pid=3582 execve guuid=639aa73c-1700-0000-dcc6-6e79000e0000 pid=3584 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=639aa73c-1700-0000-dcc6-6e79000e0000 pid=3584 execve guuid=42800b3d-1700-0000-dcc6-6e79020e0000 pid=3586 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=42800b3d-1700-0000-dcc6-6e79020e0000 pid=3586 execve guuid=34e86d3d-1700-0000-dcc6-6e79050e0000 pid=3589 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=34e86d3d-1700-0000-dcc6-6e79050e0000 pid=3589 execve guuid=76eed53d-1700-0000-dcc6-6e79070e0000 pid=3591 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=76eed53d-1700-0000-dcc6-6e79070e0000 pid=3591 execve guuid=d358363e-1700-0000-dcc6-6e79090e0000 pid=3593 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d358363e-1700-0000-dcc6-6e79090e0000 pid=3593 execve guuid=9644933e-1700-0000-dcc6-6e790c0e0000 pid=3596 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=9644933e-1700-0000-dcc6-6e790c0e0000 pid=3596 execve guuid=e22feb3e-1700-0000-dcc6-6e790e0e0000 pid=3598 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e22feb3e-1700-0000-dcc6-6e790e0e0000 pid=3598 execve guuid=37b6523f-1700-0000-dcc6-6e79110e0000 pid=3601 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=37b6523f-1700-0000-dcc6-6e79110e0000 pid=3601 execve guuid=5ee0ad3f-1700-0000-dcc6-6e79130e0000 pid=3603 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=5ee0ad3f-1700-0000-dcc6-6e79130e0000 pid=3603 execve guuid=23c60f40-1700-0000-dcc6-6e79150e0000 pid=3605 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=23c60f40-1700-0000-dcc6-6e79150e0000 pid=3605 execve guuid=e64f8040-1700-0000-dcc6-6e79180e0000 pid=3608 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e64f8040-1700-0000-dcc6-6e79180e0000 pid=3608 execve guuid=083aee40-1700-0000-dcc6-6e791a0e0000 pid=3610 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=083aee40-1700-0000-dcc6-6e791a0e0000 pid=3610 execve guuid=1d995341-1700-0000-dcc6-6e791d0e0000 pid=3613 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=1d995341-1700-0000-dcc6-6e791d0e0000 pid=3613 execve guuid=bd6dba41-1700-0000-dcc6-6e79200e0000 pid=3616 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=bd6dba41-1700-0000-dcc6-6e79200e0000 pid=3616 execve guuid=01032542-1700-0000-dcc6-6e79220e0000 pid=3618 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=01032542-1700-0000-dcc6-6e79220e0000 pid=3618 execve guuid=981da642-1700-0000-dcc6-6e79250e0000 pid=3621 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=981da642-1700-0000-dcc6-6e79250e0000 pid=3621 execve guuid=63a62943-1700-0000-dcc6-6e79270e0000 pid=3623 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=63a62943-1700-0000-dcc6-6e79270e0000 pid=3623 execve guuid=c660b843-1700-0000-dcc6-6e792d0e0000 pid=3629 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=c660b843-1700-0000-dcc6-6e792d0e0000 pid=3629 execve guuid=7bc11444-1700-0000-dcc6-6e792e0e0000 pid=3630 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=7bc11444-1700-0000-dcc6-6e792e0e0000 pid=3630 execve guuid=13997644-1700-0000-dcc6-6e79300e0000 pid=3632 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=13997644-1700-0000-dcc6-6e79300e0000 pid=3632 execve guuid=82c7db44-1700-0000-dcc6-6e79310e0000 pid=3633 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=82c7db44-1700-0000-dcc6-6e79310e0000 pid=3633 execve guuid=b58a4345-1700-0000-dcc6-6e79340e0000 pid=3636 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=b58a4345-1700-0000-dcc6-6e79340e0000 pid=3636 execve guuid=4e68a745-1700-0000-dcc6-6e79360e0000 pid=3638 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=4e68a745-1700-0000-dcc6-6e79360e0000 pid=3638 execve guuid=7b7e0446-1700-0000-dcc6-6e79390e0000 pid=3641 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=7b7e0446-1700-0000-dcc6-6e79390e0000 pid=3641 execve guuid=21266146-1700-0000-dcc6-6e793b0e0000 pid=3643 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=21266146-1700-0000-dcc6-6e793b0e0000 pid=3643 execve guuid=e5ecc246-1700-0000-dcc6-6e793d0e0000 pid=3645 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e5ecc246-1700-0000-dcc6-6e793d0e0000 pid=3645 execve guuid=7eae2d47-1700-0000-dcc6-6e793f0e0000 pid=3647 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=7eae2d47-1700-0000-dcc6-6e793f0e0000 pid=3647 execve guuid=e4d49547-1700-0000-dcc6-6e79420e0000 pid=3650 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e4d49547-1700-0000-dcc6-6e79420e0000 pid=3650 execve guuid=027df347-1700-0000-dcc6-6e79440e0000 pid=3652 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=027df347-1700-0000-dcc6-6e79440e0000 pid=3652 execve guuid=a44d5748-1700-0000-dcc6-6e79460e0000 pid=3654 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=a44d5748-1700-0000-dcc6-6e79460e0000 pid=3654 execve guuid=921db448-1700-0000-dcc6-6e79490e0000 pid=3657 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=921db448-1700-0000-dcc6-6e79490e0000 pid=3657 execve guuid=957b1649-1700-0000-dcc6-6e794a0e0000 pid=3658 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=957b1649-1700-0000-dcc6-6e794a0e0000 pid=3658 execve guuid=5ea38049-1700-0000-dcc6-6e794d0e0000 pid=3661 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=5ea38049-1700-0000-dcc6-6e794d0e0000 pid=3661 execve guuid=6d94e249-1700-0000-dcc6-6e794f0e0000 pid=3663 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=6d94e249-1700-0000-dcc6-6e794f0e0000 pid=3663 execve guuid=fb97544a-1700-0000-dcc6-6e79500e0000 pid=3664 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=fb97544a-1700-0000-dcc6-6e79500e0000 pid=3664 execve guuid=8ecec54a-1700-0000-dcc6-6e79530e0000 pid=3667 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=8ecec54a-1700-0000-dcc6-6e79530e0000 pid=3667 execve guuid=79d1334b-1700-0000-dcc6-6e79540e0000 pid=3668 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=79d1334b-1700-0000-dcc6-6e79540e0000 pid=3668 execve guuid=d109a34b-1700-0000-dcc6-6e79550e0000 pid=3669 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d109a34b-1700-0000-dcc6-6e79550e0000 pid=3669 execve guuid=49270a4c-1700-0000-dcc6-6e79560e0000 pid=3670 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=49270a4c-1700-0000-dcc6-6e79560e0000 pid=3670 execve guuid=1b1b6d4c-1700-0000-dcc6-6e79570e0000 pid=3671 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=1b1b6d4c-1700-0000-dcc6-6e79570e0000 pid=3671 execve guuid=046ae14c-1700-0000-dcc6-6e79580e0000 pid=3672 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=046ae14c-1700-0000-dcc6-6e79580e0000 pid=3672 execve guuid=52d3434d-1700-0000-dcc6-6e79590e0000 pid=3673 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=52d3434d-1700-0000-dcc6-6e79590e0000 pid=3673 execve guuid=6742b04d-1700-0000-dcc6-6e795a0e0000 pid=3674 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=6742b04d-1700-0000-dcc6-6e795a0e0000 pid=3674 execve guuid=da45104e-1700-0000-dcc6-6e795b0e0000 pid=3675 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=da45104e-1700-0000-dcc6-6e795b0e0000 pid=3675 execve guuid=f54e824e-1700-0000-dcc6-6e795c0e0000 pid=3676 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f54e824e-1700-0000-dcc6-6e795c0e0000 pid=3676 execve guuid=54e5df4e-1700-0000-dcc6-6e795d0e0000 pid=3677 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=54e5df4e-1700-0000-dcc6-6e795d0e0000 pid=3677 execve guuid=f5ef474f-1700-0000-dcc6-6e795e0e0000 pid=3678 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f5ef474f-1700-0000-dcc6-6e795e0e0000 pid=3678 execve guuid=bcf1a64f-1700-0000-dcc6-6e795f0e0000 pid=3679 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=bcf1a64f-1700-0000-dcc6-6e795f0e0000 pid=3679 execve guuid=50e20850-1700-0000-dcc6-6e79600e0000 pid=3680 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=50e20850-1700-0000-dcc6-6e79600e0000 pid=3680 execve guuid=36396450-1700-0000-dcc6-6e79610e0000 pid=3681 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=36396450-1700-0000-dcc6-6e79610e0000 pid=3681 execve guuid=3c7bc050-1700-0000-dcc6-6e79620e0000 pid=3682 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=3c7bc050-1700-0000-dcc6-6e79620e0000 pid=3682 execve guuid=e4b71d51-1700-0000-dcc6-6e79630e0000 pid=3683 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e4b71d51-1700-0000-dcc6-6e79630e0000 pid=3683 execve guuid=98589851-1700-0000-dcc6-6e79640e0000 pid=3684 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=98589851-1700-0000-dcc6-6e79640e0000 pid=3684 execve guuid=88af1f52-1700-0000-dcc6-6e79670e0000 pid=3687 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=88af1f52-1700-0000-dcc6-6e79670e0000 pid=3687 execve guuid=8fb79d52-1700-0000-dcc6-6e79690e0000 pid=3689 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=8fb79d52-1700-0000-dcc6-6e79690e0000 pid=3689 execve guuid=eb231553-1700-0000-dcc6-6e796b0e0000 pid=3691 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=eb231553-1700-0000-dcc6-6e796b0e0000 pid=3691 execve guuid=33aa8e53-1700-0000-dcc6-6e796d0e0000 pid=3693 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=33aa8e53-1700-0000-dcc6-6e796d0e0000 pid=3693 execve guuid=5c650254-1700-0000-dcc6-6e796e0e0000 pid=3694 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=5c650254-1700-0000-dcc6-6e796e0e0000 pid=3694 execve guuid=de558654-1700-0000-dcc6-6e796f0e0000 pid=3695 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=de558654-1700-0000-dcc6-6e796f0e0000 pid=3695 execve guuid=e98bf154-1700-0000-dcc6-6e79700e0000 pid=3696 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e98bf154-1700-0000-dcc6-6e79700e0000 pid=3696 execve guuid=bc627855-1700-0000-dcc6-6e79710e0000 pid=3697 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=bc627855-1700-0000-dcc6-6e79710e0000 pid=3697 execve guuid=a143f855-1700-0000-dcc6-6e79740e0000 pid=3700 /usr/bin/ls guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=a143f855-1700-0000-dcc6-6e79740e0000 pid=3700 execve guuid=d13a7856-1700-0000-dcc6-6e79760e0000 pid=3702 /usr/bin/rm guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d13a7856-1700-0000-dcc6-6e79760e0000 pid=3702 execve guuid=030ec856-1700-0000-dcc6-6e79770e0000 pid=3703 /usr/bin/wget net send-data write-file guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=030ec856-1700-0000-dcc6-6e79770e0000 pid=3703 execve guuid=00650f5f-1700-0000-dcc6-6e79890e0000 pid=3721 /usr/bin/chmod guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=00650f5f-1700-0000-dcc6-6e79890e0000 pid=3721 execve guuid=40e5655f-1700-0000-dcc6-6e798b0e0000 pid=3723 /tmp/Xd1o guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=40e5655f-1700-0000-dcc6-6e798b0e0000 pid=3723 execve guuid=f84f5e60-1700-0000-dcc6-6e79900e0000 pid=3728 /usr/bin/rm guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f84f5e60-1700-0000-dcc6-6e79900e0000 pid=3728 execve guuid=1374c460-1700-0000-dcc6-6e79920e0000 pid=3730 /usr/bin/wget net send-data write-file guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=1374c460-1700-0000-dcc6-6e79920e0000 pid=3730 execve guuid=2c358469-1700-0000-dcc6-6e79a70e0000 pid=3751 /usr/bin/chmod guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=2c358469-1700-0000-dcc6-6e79a70e0000 pid=3751 execve guuid=ad72e869-1700-0000-dcc6-6e79a90e0000 pid=3753 /tmp/j9E4 guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=ad72e869-1700-0000-dcc6-6e79a90e0000 pid=3753 execve guuid=75f2a56b-1700-0000-dcc6-6e79ae0e0000 pid=3758 /usr/bin/rm guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=75f2a56b-1700-0000-dcc6-6e79ae0e0000 pid=3758 execve guuid=5255f26b-1700-0000-dcc6-6e79b20e0000 pid=3762 /usr/bin/wget net send-data write-file guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=5255f26b-1700-0000-dcc6-6e79b20e0000 pid=3762 execve guuid=ead959af-1700-0000-dcc6-6e79520f0000 pid=3922 /usr/bin/chmod guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=ead959af-1700-0000-dcc6-6e79520f0000 pid=3922 execve guuid=24319eaf-1700-0000-dcc6-6e79550f0000 pid=3925 /tmp/jAA guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=24319eaf-1700-0000-dcc6-6e79550f0000 pid=3925 execve guuid=e09764b0-1700-0000-dcc6-6e795c0f0000 pid=3932 /usr/bin/rm guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=e09764b0-1700-0000-dcc6-6e795c0f0000 pid=3932 execve guuid=f873a1b0-1700-0000-dcc6-6e795f0f0000 pid=3935 /usr/bin/wget net send-data write-file guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=f873a1b0-1700-0000-dcc6-6e795f0f0000 pid=3935 execve guuid=3009e4b7-1700-0000-dcc6-6e79770f0000 pid=3959 /usr/bin/chmod guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=3009e4b7-1700-0000-dcc6-6e79770f0000 pid=3959 execve guuid=2e681fb8-1700-0000-dcc6-6e79780f0000 pid=3960 /tmp/FwWD guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=2e681fb8-1700-0000-dcc6-6e79780f0000 pid=3960 execve guuid=26bf0bb9-1700-0000-dcc6-6e797c0f0000 pid=3964 /usr/bin/rm guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=26bf0bb9-1700-0000-dcc6-6e797c0f0000 pid=3964 execve guuid=d4e34ab9-1700-0000-dcc6-6e79800f0000 pid=3968 /usr/bin/wget net send-data write-file guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d4e34ab9-1700-0000-dcc6-6e79800f0000 pid=3968 execve guuid=c9583ade-1700-0000-dcc6-6e79e50f0000 pid=4069 /usr/bin/chmod guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=c9583ade-1700-0000-dcc6-6e79e50f0000 pid=4069 execve guuid=d16b90de-1700-0000-dcc6-6e79e70f0000 pid=4071 /tmp/rVy guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=d16b90de-1700-0000-dcc6-6e79e70f0000 pid=4071 execve guuid=64d6a9df-1700-0000-dcc6-6e79ec0f0000 pid=4076 /usr/bin/rm delete-file guuid=608a1024-1700-0000-dcc6-6e79910d0000 pid=3473->guuid=64d6a9df-1700-0000-dcc6-6e79ec0f0000 pid=4076 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=030ec856-1700-0000-dcc6-6e79770e0000 pid=3703->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=1374c460-1700-0000-dcc6-6e79920e0000 pid=3730->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=5255f26b-1700-0000-dcc6-6e79b20e0000 pid=3762->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=f873a1b0-1700-0000-dcc6-6e795f0f0000 pid=3935->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=d4e34ab9-1700-0000-dcc6-6e79800f0000 pid=3968->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-02 08:07:34 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f7d98e451b7acb40adea1b84e5df78431e8bf128a7d48dcb5222e4150dd2e805

(this sample)

  
Delivery method
Distributed via web download

Comments