MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb52958eb7a003540263b299b0efc77ce3263fc090f666ec00a832fa9a546e38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: fb52958eb7a003540263b299b0efc77ce3263fc090f666ec00a832fa9a546e38
SHA3-384 hash: 0590fe9e6eb970089bb952b21680e728813f2268f5ab95eee9e698100792e499ad0a041fec54af897de052c04c983e47
SHA1 hash: ca9a98d7a0e9ca20ae4f95800883259e413a23f2
MD5 hash: 205d15ca1df6a70f7a2a375c1f92690c
humanhash: west-pennsylvania-summer-wisconsin
File name:p
Download: download sample
File size:826 bytes
First seen:2026-06-03 16:45:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkavFIQcuSIQmxKXI9SbOFI0WWh4EISZWkaa:kXCKysE2hi0ziQvZohadrSTalFDqk7
TLSH T1A601CEC9C502979040D9E86E32D76284B421C3CB16466FB87F9C503EEBAD708B015FEC
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=23840a93-1600-0000-86f5-fcbbb30b0000 pid=2995 /usr/bin/sudo guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001 /tmp/sample.bin write-file guuid=23840a93-1600-0000-86f5-fcbbb30b0000 pid=2995->guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001 execve guuid=d6b3ce95-1600-0000-86f5-fcbbbb0b0000 pid=3003 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d6b3ce95-1600-0000-86f5-fcbbbb0b0000 pid=3003 execve guuid=277e6596-1600-0000-86f5-fcbbbd0b0000 pid=3005 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=277e6596-1600-0000-86f5-fcbbbd0b0000 pid=3005 execve guuid=527fd296-1600-0000-86f5-fcbbbf0b0000 pid=3007 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=527fd296-1600-0000-86f5-fcbbbf0b0000 pid=3007 execve guuid=2b693f97-1600-0000-86f5-fcbbc20b0000 pid=3010 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2b693f97-1600-0000-86f5-fcbbc20b0000 pid=3010 execve guuid=7ac2a597-1600-0000-86f5-fcbbc40b0000 pid=3012 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=7ac2a597-1600-0000-86f5-fcbbc40b0000 pid=3012 execve guuid=6bae1098-1600-0000-86f5-fcbbc70b0000 pid=3015 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6bae1098-1600-0000-86f5-fcbbc70b0000 pid=3015 execve guuid=314c9598-1600-0000-86f5-fcbbc90b0000 pid=3017 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=314c9598-1600-0000-86f5-fcbbc90b0000 pid=3017 execve guuid=2a400499-1600-0000-86f5-fcbbcb0b0000 pid=3019 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2a400499-1600-0000-86f5-fcbbcb0b0000 pid=3019 execve guuid=0bca6499-1600-0000-86f5-fcbbcd0b0000 pid=3021 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0bca6499-1600-0000-86f5-fcbbcd0b0000 pid=3021 execve guuid=8ececa99-1600-0000-86f5-fcbbcf0b0000 pid=3023 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8ececa99-1600-0000-86f5-fcbbcf0b0000 pid=3023 execve guuid=0e44299a-1600-0000-86f5-fcbbd20b0000 pid=3026 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0e44299a-1600-0000-86f5-fcbbd20b0000 pid=3026 execve guuid=8819079b-1600-0000-86f5-fcbbd60b0000 pid=3030 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8819079b-1600-0000-86f5-fcbbd60b0000 pid=3030 execve guuid=0fa4709b-1600-0000-86f5-fcbbd80b0000 pid=3032 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0fa4709b-1600-0000-86f5-fcbbd80b0000 pid=3032 execve guuid=6438d59b-1600-0000-86f5-fcbbdb0b0000 pid=3035 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6438d59b-1600-0000-86f5-fcbbdb0b0000 pid=3035 execve guuid=2339379c-1600-0000-86f5-fcbbdd0b0000 pid=3037 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2339379c-1600-0000-86f5-fcbbdd0b0000 pid=3037 execve guuid=c6619b9c-1600-0000-86f5-fcbbe00b0000 pid=3040 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=c6619b9c-1600-0000-86f5-fcbbe00b0000 pid=3040 execve guuid=3f36019d-1600-0000-86f5-fcbbe10b0000 pid=3041 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=3f36019d-1600-0000-86f5-fcbbe10b0000 pid=3041 execve guuid=6d65689d-1600-0000-86f5-fcbbe30b0000 pid=3043 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6d65689d-1600-0000-86f5-fcbbe30b0000 pid=3043 execve guuid=a0c6e59d-1600-0000-86f5-fcbbe40b0000 pid=3044 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a0c6e59d-1600-0000-86f5-fcbbe40b0000 pid=3044 execve guuid=5e41599e-1600-0000-86f5-fcbbe50b0000 pid=3045 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=5e41599e-1600-0000-86f5-fcbbe50b0000 pid=3045 execve guuid=3b65c39e-1600-0000-86f5-fcbbe70b0000 pid=3047 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=3b65c39e-1600-0000-86f5-fcbbe70b0000 pid=3047 execve guuid=7f242a9f-1600-0000-86f5-fcbbea0b0000 pid=3050 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=7f242a9f-1600-0000-86f5-fcbbea0b0000 pid=3050 execve guuid=8f8a899f-1600-0000-86f5-fcbbec0b0000 pid=3052 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8f8a899f-1600-0000-86f5-fcbbec0b0000 pid=3052 execve guuid=8ebee49f-1600-0000-86f5-fcbbee0b0000 pid=3054 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8ebee49f-1600-0000-86f5-fcbbee0b0000 pid=3054 execve guuid=6a5d45a0-1600-0000-86f5-fcbbf10b0000 pid=3057 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6a5d45a0-1600-0000-86f5-fcbbf10b0000 pid=3057 execve guuid=2b559ea0-1600-0000-86f5-fcbbf30b0000 pid=3059 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2b559ea0-1600-0000-86f5-fcbbf30b0000 pid=3059 execve guuid=ea43fca0-1600-0000-86f5-fcbbf60b0000 pid=3062 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=ea43fca0-1600-0000-86f5-fcbbf60b0000 pid=3062 execve guuid=123a59a1-1600-0000-86f5-fcbbf80b0000 pid=3064 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=123a59a1-1600-0000-86f5-fcbbf80b0000 pid=3064 execve guuid=0e9db3a1-1600-0000-86f5-fcbbfa0b0000 pid=3066 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0e9db3a1-1600-0000-86f5-fcbbfa0b0000 pid=3066 execve guuid=040e1ea2-1600-0000-86f5-fcbbfc0b0000 pid=3068 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=040e1ea2-1600-0000-86f5-fcbbfc0b0000 pid=3068 execve guuid=33d98ba2-1600-0000-86f5-fcbbfd0b0000 pid=3069 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=33d98ba2-1600-0000-86f5-fcbbfd0b0000 pid=3069 execve guuid=ece3f7a2-1600-0000-86f5-fcbbff0b0000 pid=3071 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=ece3f7a2-1600-0000-86f5-fcbbff0b0000 pid=3071 execve guuid=a80e5fa3-1600-0000-86f5-fcbb010c0000 pid=3073 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a80e5fa3-1600-0000-86f5-fcbb010c0000 pid=3073 execve guuid=d6dbc2a3-1600-0000-86f5-fcbb030c0000 pid=3075 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d6dbc2a3-1600-0000-86f5-fcbb030c0000 pid=3075 execve guuid=91b129a4-1600-0000-86f5-fcbb060c0000 pid=3078 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=91b129a4-1600-0000-86f5-fcbb060c0000 pid=3078 execve guuid=d4438ba4-1600-0000-86f5-fcbb080c0000 pid=3080 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d4438ba4-1600-0000-86f5-fcbb080c0000 pid=3080 execve guuid=06b1efa4-1600-0000-86f5-fcbb0b0c0000 pid=3083 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=06b1efa4-1600-0000-86f5-fcbb0b0c0000 pid=3083 execve guuid=e79248a5-1600-0000-86f5-fcbb0d0c0000 pid=3085 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=e79248a5-1600-0000-86f5-fcbb0d0c0000 pid=3085 execve guuid=4fa3a3a5-1600-0000-86f5-fcbb0f0c0000 pid=3087 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=4fa3a3a5-1600-0000-86f5-fcbb0f0c0000 pid=3087 execve guuid=5103fea5-1600-0000-86f5-fcbb120c0000 pid=3090 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=5103fea5-1600-0000-86f5-fcbb120c0000 pid=3090 execve guuid=484d53a6-1600-0000-86f5-fcbb140c0000 pid=3092 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=484d53a6-1600-0000-86f5-fcbb140c0000 pid=3092 execve guuid=c0b0aba6-1600-0000-86f5-fcbb170c0000 pid=3095 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=c0b0aba6-1600-0000-86f5-fcbb170c0000 pid=3095 execve guuid=3ee5fca6-1600-0000-86f5-fcbb190c0000 pid=3097 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=3ee5fca6-1600-0000-86f5-fcbb190c0000 pid=3097 execve guuid=85f356a7-1600-0000-86f5-fcbb1b0c0000 pid=3099 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=85f356a7-1600-0000-86f5-fcbb1b0c0000 pid=3099 execve guuid=dd87afa7-1600-0000-86f5-fcbb1e0c0000 pid=3102 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=dd87afa7-1600-0000-86f5-fcbb1e0c0000 pid=3102 execve guuid=cc8a06a8-1600-0000-86f5-fcbb200c0000 pid=3104 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=cc8a06a8-1600-0000-86f5-fcbb200c0000 pid=3104 execve guuid=713a5ba8-1600-0000-86f5-fcbb220c0000 pid=3106 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=713a5ba8-1600-0000-86f5-fcbb220c0000 pid=3106 execve guuid=29e1b7a8-1600-0000-86f5-fcbb240c0000 pid=3108 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=29e1b7a8-1600-0000-86f5-fcbb240c0000 pid=3108 execve guuid=9e6e0ea9-1600-0000-86f5-fcbb270c0000 pid=3111 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=9e6e0ea9-1600-0000-86f5-fcbb270c0000 pid=3111 execve guuid=b0295ea9-1600-0000-86f5-fcbb290c0000 pid=3113 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=b0295ea9-1600-0000-86f5-fcbb290c0000 pid=3113 execve guuid=5cd5bfa9-1600-0000-86f5-fcbb2b0c0000 pid=3115 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=5cd5bfa9-1600-0000-86f5-fcbb2b0c0000 pid=3115 execve guuid=b1f624aa-1600-0000-86f5-fcbb2e0c0000 pid=3118 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=b1f624aa-1600-0000-86f5-fcbb2e0c0000 pid=3118 execve guuid=2c2da5aa-1600-0000-86f5-fcbb300c0000 pid=3120 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2c2da5aa-1600-0000-86f5-fcbb300c0000 pid=3120 execve guuid=880711ab-1600-0000-86f5-fcbb320c0000 pid=3122 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=880711ab-1600-0000-86f5-fcbb320c0000 pid=3122 execve guuid=719d84ab-1600-0000-86f5-fcbb350c0000 pid=3125 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=719d84ab-1600-0000-86f5-fcbb350c0000 pid=3125 execve guuid=99fde7ab-1600-0000-86f5-fcbb380c0000 pid=3128 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=99fde7ab-1600-0000-86f5-fcbb380c0000 pid=3128 execve guuid=a8183fac-1600-0000-86f5-fcbb3a0c0000 pid=3130 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a8183fac-1600-0000-86f5-fcbb3a0c0000 pid=3130 execve guuid=1ddc95ac-1600-0000-86f5-fcbb3c0c0000 pid=3132 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=1ddc95ac-1600-0000-86f5-fcbb3c0c0000 pid=3132 execve guuid=d8c4f1ac-1600-0000-86f5-fcbb400c0000 pid=3136 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d8c4f1ac-1600-0000-86f5-fcbb400c0000 pid=3136 execve guuid=a85767ad-1600-0000-86f5-fcbb410c0000 pid=3137 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a85767ad-1600-0000-86f5-fcbb410c0000 pid=3137 execve guuid=61a1c5ad-1600-0000-86f5-fcbb420c0000 pid=3138 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=61a1c5ad-1600-0000-86f5-fcbb420c0000 pid=3138 execve guuid=93c221ae-1600-0000-86f5-fcbb430c0000 pid=3139 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=93c221ae-1600-0000-86f5-fcbb430c0000 pid=3139 execve guuid=1a8978ae-1600-0000-86f5-fcbb450c0000 pid=3141 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=1a8978ae-1600-0000-86f5-fcbb450c0000 pid=3141 execve guuid=56e0cbae-1600-0000-86f5-fcbb480c0000 pid=3144 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=56e0cbae-1600-0000-86f5-fcbb480c0000 pid=3144 execve guuid=4c9729af-1600-0000-86f5-fcbb4a0c0000 pid=3146 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=4c9729af-1600-0000-86f5-fcbb4a0c0000 pid=3146 execve guuid=bd8f81af-1600-0000-86f5-fcbb4c0c0000 pid=3148 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=bd8f81af-1600-0000-86f5-fcbb4c0c0000 pid=3148 execve guuid=a535e8af-1600-0000-86f5-fcbb4f0c0000 pid=3151 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a535e8af-1600-0000-86f5-fcbb4f0c0000 pid=3151 execve guuid=970a4eb0-1600-0000-86f5-fcbb510c0000 pid=3153 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=970a4eb0-1600-0000-86f5-fcbb510c0000 pid=3153 execve guuid=35eea9b0-1600-0000-86f5-fcbb540c0000 pid=3156 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=35eea9b0-1600-0000-86f5-fcbb540c0000 pid=3156 execve guuid=5cc313b1-1600-0000-86f5-fcbb550c0000 pid=3157 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=5cc313b1-1600-0000-86f5-fcbb550c0000 pid=3157 execve guuid=a28e91b1-1600-0000-86f5-fcbb560c0000 pid=3158 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a28e91b1-1600-0000-86f5-fcbb560c0000 pid=3158 execve guuid=478713b2-1600-0000-86f5-fcbb580c0000 pid=3160 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=478713b2-1600-0000-86f5-fcbb580c0000 pid=3160 execve guuid=6524aab2-1600-0000-86f5-fcbb590c0000 pid=3161 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6524aab2-1600-0000-86f5-fcbb590c0000 pid=3161 execve guuid=81bb3eb3-1600-0000-86f5-fcbb5a0c0000 pid=3162 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=81bb3eb3-1600-0000-86f5-fcbb5a0c0000 pid=3162 execve guuid=6362b9b3-1600-0000-86f5-fcbb5c0c0000 pid=3164 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6362b9b3-1600-0000-86f5-fcbb5c0c0000 pid=3164 execve guuid=c1ab22b4-1600-0000-86f5-fcbb5f0c0000 pid=3167 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=c1ab22b4-1600-0000-86f5-fcbb5f0c0000 pid=3167 execve guuid=4ea98bb4-1600-0000-86f5-fcbb610c0000 pid=3169 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=4ea98bb4-1600-0000-86f5-fcbb610c0000 pid=3169 execve guuid=d69aeeb4-1600-0000-86f5-fcbb640c0000 pid=3172 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d69aeeb4-1600-0000-86f5-fcbb640c0000 pid=3172 execve guuid=819a52b5-1600-0000-86f5-fcbb660c0000 pid=3174 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=819a52b5-1600-0000-86f5-fcbb660c0000 pid=3174 execve guuid=8693beb5-1600-0000-86f5-fcbb670c0000 pid=3175 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8693beb5-1600-0000-86f5-fcbb670c0000 pid=3175 execve guuid=cf032eb6-1600-0000-86f5-fcbb680c0000 pid=3176 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=cf032eb6-1600-0000-86f5-fcbb680c0000 pid=3176 execve guuid=fa4690b6-1600-0000-86f5-fcbb6a0c0000 pid=3178 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=fa4690b6-1600-0000-86f5-fcbb6a0c0000 pid=3178 execve guuid=8af7eeb6-1600-0000-86f5-fcbb6c0c0000 pid=3180 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8af7eeb6-1600-0000-86f5-fcbb6c0c0000 pid=3180 execve guuid=3cdf4bb7-1600-0000-86f5-fcbb6e0c0000 pid=3182 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=3cdf4bb7-1600-0000-86f5-fcbb6e0c0000 pid=3182 execve guuid=66e4a9b7-1600-0000-86f5-fcbb710c0000 pid=3185 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=66e4a9b7-1600-0000-86f5-fcbb710c0000 pid=3185 execve guuid=83410db8-1600-0000-86f5-fcbb730c0000 pid=3187 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=83410db8-1600-0000-86f5-fcbb730c0000 pid=3187 execve guuid=9f0974b8-1600-0000-86f5-fcbb750c0000 pid=3189 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=9f0974b8-1600-0000-86f5-fcbb750c0000 pid=3189 execve guuid=182e48b9-1600-0000-86f5-fcbb760c0000 pid=3190 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=182e48b9-1600-0000-86f5-fcbb760c0000 pid=3190 execve guuid=00aed6b9-1600-0000-86f5-fcbb770c0000 pid=3191 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=00aed6b9-1600-0000-86f5-fcbb770c0000 pid=3191 execve guuid=39c24aba-1600-0000-86f5-fcbb790c0000 pid=3193 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=39c24aba-1600-0000-86f5-fcbb790c0000 pid=3193 execve guuid=e24facba-1600-0000-86f5-fcbb7c0c0000 pid=3196 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=e24facba-1600-0000-86f5-fcbb7c0c0000 pid=3196 execve guuid=887c0cbb-1600-0000-86f5-fcbb7e0c0000 pid=3198 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=887c0cbb-1600-0000-86f5-fcbb7e0c0000 pid=3198 execve guuid=289568bb-1600-0000-86f5-fcbb800c0000 pid=3200 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=289568bb-1600-0000-86f5-fcbb800c0000 pid=3200 execve guuid=819fc0bb-1600-0000-86f5-fcbb820c0000 pid=3202 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=819fc0bb-1600-0000-86f5-fcbb820c0000 pid=3202 execve guuid=bfc433bc-1600-0000-86f5-fcbb830c0000 pid=3203 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=bfc433bc-1600-0000-86f5-fcbb830c0000 pid=3203 execve guuid=a07323bd-1600-0000-86f5-fcbb840c0000 pid=3204 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a07323bd-1600-0000-86f5-fcbb840c0000 pid=3204 execve guuid=a8dc9fbd-1600-0000-86f5-fcbb850c0000 pid=3205 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a8dc9fbd-1600-0000-86f5-fcbb850c0000 pid=3205 execve guuid=0dcc19be-1600-0000-86f5-fcbb860c0000 pid=3206 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0dcc19be-1600-0000-86f5-fcbb860c0000 pid=3206 execve guuid=fd3293be-1600-0000-86f5-fcbb870c0000 pid=3207 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=fd3293be-1600-0000-86f5-fcbb870c0000 pid=3207 execve guuid=2af30cbf-1600-0000-86f5-fcbb880c0000 pid=3208 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2af30cbf-1600-0000-86f5-fcbb880c0000 pid=3208 execve guuid=b7288abf-1600-0000-86f5-fcbb890c0000 pid=3209 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=b7288abf-1600-0000-86f5-fcbb890c0000 pid=3209 execve guuid=0febfdbf-1600-0000-86f5-fcbb8a0c0000 pid=3210 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0febfdbf-1600-0000-86f5-fcbb8a0c0000 pid=3210 execve guuid=da3872c0-1600-0000-86f5-fcbb8b0c0000 pid=3211 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=da3872c0-1600-0000-86f5-fcbb8b0c0000 pid=3211 execve guuid=cd38f1c0-1600-0000-86f5-fcbb8c0c0000 pid=3212 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=cd38f1c0-1600-0000-86f5-fcbb8c0c0000 pid=3212 execve guuid=f94167c1-1600-0000-86f5-fcbb8d0c0000 pid=3213 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=f94167c1-1600-0000-86f5-fcbb8d0c0000 pid=3213 execve guuid=51dddec1-1600-0000-86f5-fcbb8e0c0000 pid=3214 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=51dddec1-1600-0000-86f5-fcbb8e0c0000 pid=3214 execve guuid=624a5ac2-1600-0000-86f5-fcbb8f0c0000 pid=3215 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=624a5ac2-1600-0000-86f5-fcbb8f0c0000 pid=3215 execve guuid=1bffd7c2-1600-0000-86f5-fcbb900c0000 pid=3216 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=1bffd7c2-1600-0000-86f5-fcbb900c0000 pid=3216 execve guuid=ca7050c3-1600-0000-86f5-fcbb910c0000 pid=3217 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=ca7050c3-1600-0000-86f5-fcbb910c0000 pid=3217 execve guuid=7893cbc3-1600-0000-86f5-fcbb920c0000 pid=3218 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=7893cbc3-1600-0000-86f5-fcbb920c0000 pid=3218 execve guuid=e4cf53c4-1600-0000-86f5-fcbb930c0000 pid=3219 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=e4cf53c4-1600-0000-86f5-fcbb930c0000 pid=3219 execve guuid=a09bcfc4-1600-0000-86f5-fcbb940c0000 pid=3220 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a09bcfc4-1600-0000-86f5-fcbb940c0000 pid=3220 execve guuid=6f2750c5-1600-0000-86f5-fcbb950c0000 pid=3221 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6f2750c5-1600-0000-86f5-fcbb950c0000 pid=3221 execve guuid=39dfccc5-1600-0000-86f5-fcbb960c0000 pid=3222 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=39dfccc5-1600-0000-86f5-fcbb960c0000 pid=3222 execve guuid=78b152c6-1600-0000-86f5-fcbb970c0000 pid=3223 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=78b152c6-1600-0000-86f5-fcbb970c0000 pid=3223 execve guuid=76abd3c6-1600-0000-86f5-fcbb980c0000 pid=3224 /usr/bin/ls guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=76abd3c6-1600-0000-86f5-fcbb980c0000 pid=3224 execve guuid=0a3755c7-1600-0000-86f5-fcbb990c0000 pid=3225 /usr/bin/rm guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0a3755c7-1600-0000-86f5-fcbb990c0000 pid=3225 execve guuid=9cd7a5c7-1600-0000-86f5-fcbb9a0c0000 pid=3226 /usr/bin/wget net send-data write-file guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=9cd7a5c7-1600-0000-86f5-fcbb9a0c0000 pid=3226 execve guuid=74b34841-1900-0000-86f5-fcbba8110000 pid=4520 /usr/bin/chmod guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=74b34841-1900-0000-86f5-fcbba8110000 pid=4520 execve guuid=d492c541-1900-0000-86f5-fcbbaa110000 pid=4522 /usr/bin/dash guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d492c541-1900-0000-86f5-fcbbaa110000 pid=4522 clone guuid=38c1c342-1900-0000-86f5-fcbbad110000 pid=4525 /usr/bin/rm guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=38c1c342-1900-0000-86f5-fcbbad110000 pid=4525 execve guuid=75225d43-1900-0000-86f5-fcbbb1110000 pid=4529 /usr/bin/wget net send-data write-file guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=75225d43-1900-0000-86f5-fcbbb1110000 pid=4529 execve guuid=253d11dc-1900-0000-86f5-fcbb37130000 pid=4919 /usr/bin/chmod guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=253d11dc-1900-0000-86f5-fcbb37130000 pid=4919 execve guuid=e3f8a9dc-1900-0000-86f5-fcbb39130000 pid=4921 /usr/bin/dash guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=e3f8a9dc-1900-0000-86f5-fcbb39130000 pid=4921 clone guuid=e2db30de-1900-0000-86f5-fcbb3d130000 pid=4925 /usr/bin/rm guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=e2db30de-1900-0000-86f5-fcbb3d130000 pid=4925 execve guuid=f5399dde-1900-0000-86f5-fcbb3f130000 pid=4927 /usr/bin/wget net send-data write-file guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=f5399dde-1900-0000-86f5-fcbb3f130000 pid=4927 execve guuid=0767f4ec-1a00-0000-86f5-fcbbdd140000 pid=5341 /usr/bin/chmod guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=0767f4ec-1a00-0000-86f5-fcbbdd140000 pid=5341 execve guuid=d31ba0ed-1a00-0000-86f5-fcbbde140000 pid=5342 /usr/bin/dash guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=d31ba0ed-1a00-0000-86f5-fcbbde140000 pid=5342 clone guuid=c4e32cef-1a00-0000-86f5-fcbbe0140000 pid=5344 /usr/bin/rm guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=c4e32cef-1a00-0000-86f5-fcbbe0140000 pid=5344 execve guuid=65e2e3ef-1a00-0000-86f5-fcbbe1140000 pid=5345 /usr/bin/wget net send-data write-file guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=65e2e3ef-1a00-0000-86f5-fcbbe1140000 pid=5345 execve guuid=3335c797-1c00-0000-86f5-fcbbf7140000 pid=5367 /usr/bin/chmod guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=3335c797-1c00-0000-86f5-fcbbf7140000 pid=5367 execve guuid=88110698-1c00-0000-86f5-fcbbf8140000 pid=5368 /usr/bin/dash guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=88110698-1c00-0000-86f5-fcbbf8140000 pid=5368 clone guuid=2597b498-1c00-0000-86f5-fcbbfa140000 pid=5370 /usr/bin/rm guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=2597b498-1c00-0000-86f5-fcbbfa140000 pid=5370 execve guuid=6a88fd98-1c00-0000-86f5-fcbbfb140000 pid=5371 /usr/bin/wget net send-data write-file guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=6a88fd98-1c00-0000-86f5-fcbbfb140000 pid=5371 execve guuid=22f6db16-1e00-0000-86f5-fcbb0f150000 pid=5391 /usr/bin/chmod guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=22f6db16-1e00-0000-86f5-fcbb0f150000 pid=5391 execve guuid=a2ce6617-1e00-0000-86f5-fcbb10150000 pid=5392 /usr/bin/dash guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=a2ce6617-1e00-0000-86f5-fcbb10150000 pid=5392 clone guuid=8930ae18-1e00-0000-86f5-fcbb12150000 pid=5394 /usr/bin/rm delete-file guuid=bfde6395-1600-0000-86f5-fcbbb90b0000 pid=3001->guuid=8930ae18-1e00-0000-86f5-fcbb12150000 pid=5394 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=9cd7a5c7-1600-0000-86f5-fcbb9a0c0000 pid=3226->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=75225d43-1900-0000-86f5-fcbbb1110000 pid=4529->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=f5399dde-1900-0000-86f5-fcbb3f130000 pid=4927->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=65e2e3ef-1a00-0000-86f5-fcbbe1140000 pid=5345->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=6a88fd98-1c00-0000-86f5-fcbbfb140000 pid=5371->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-03 16:46:30 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fb52958eb7a003540263b299b0efc77ce3263fc090f666ec00a832fa9a546e38

(this sample)

  
Delivery method
Distributed via web download

Comments