MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe2e5dc794bf4bebe2092e45422fe5f9c5e8083e7ef32b5f9c17018941e19fa1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: fe2e5dc794bf4bebe2092e45422fe5f9c5e8083e7ef32b5f9c17018941e19fa1
SHA3-384 hash: 122c4d2f5587b60047c9f6d3a47cc27d92d1a712953b4520b4473e329a92da8e53b9d90046c32ac69500fe050bd9e23e
SHA1 hash: 0de5bb0435d34ef39e8711f8fd651cb14cd01234
MD5 hash: 4d50c4e095a68108c8602d9df24dc703
humanhash: september-washington-twelve-nitrogen
File name:wr.php
Download: download sample
File size:27'042 bytes
First seen:2026-07-23 22:32:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 768:0G8vCB+25j6es8RV9FYpMSUpi+20qUpi+20YQX:0G8l25Jzd2QX
TLSH T1A0C28D966A867C44BEC94A3E4CBD2B1D6DF5C3D1324942AC3D8B3C719C11FACD618B1A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.119.69.4/z/post/noroot.phpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade
Status:
terminated
Behavior Graph:
%3 guuid=ec9d06a8-1800-0000-6512-baddf6120000 pid=4854 /usr/bin/sudo guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857 /tmp/sample.bin guuid=ec9d06a8-1800-0000-6512-baddf6120000 pid=4854->guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857 execve guuid=22ea74aa-1800-0000-6512-baddfd120000 pid=4861 /usr/bin/bash guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=22ea74aa-1800-0000-6512-baddfd120000 pid=4861 clone guuid=880a7baa-1800-0000-6512-baddfe120000 pid=4862 /usr/bin/base64 guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=880a7baa-1800-0000-6512-baddfe120000 pid=4862 execve guuid=800281aa-1800-0000-6512-baddff120000 pid=4863 /usr/bin/bash guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=800281aa-1800-0000-6512-baddff120000 pid=4863 clone guuid=6c4ff9aa-1800-0000-6512-badd03130000 pid=4867 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=6c4ff9aa-1800-0000-6512-badd03130000 pid=4867 execve guuid=550c5aab-1800-0000-6512-badd05130000 pid=4869 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=550c5aab-1800-0000-6512-badd05130000 pid=4869 execve guuid=186ab0ab-1800-0000-6512-badd08130000 pid=4872 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=186ab0ab-1800-0000-6512-badd08130000 pid=4872 execve guuid=8277ffab-1800-0000-6512-badd0b130000 pid=4875 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=8277ffab-1800-0000-6512-badd0b130000 pid=4875 execve guuid=45084bac-1800-0000-6512-badd0f130000 pid=4879 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=45084bac-1800-0000-6512-badd0f130000 pid=4879 execve guuid=8481a0ac-1800-0000-6512-badd11130000 pid=4881 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=8481a0ac-1800-0000-6512-badd11130000 pid=4881 execve guuid=4f85faac-1800-0000-6512-badd13130000 pid=4883 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=4f85faac-1800-0000-6512-badd13130000 pid=4883 execve guuid=5da654ad-1800-0000-6512-badd17130000 pid=4887 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=5da654ad-1800-0000-6512-badd17130000 pid=4887 execve guuid=7c34b5ad-1800-0000-6512-badd18130000 pid=4888 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=7c34b5ad-1800-0000-6512-badd18130000 pid=4888 execve guuid=5c0132ae-1800-0000-6512-badd1c130000 pid=4892 /usr/bin/mkdir guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=5c0132ae-1800-0000-6512-badd1c130000 pid=4892 execve guuid=818383ae-1800-0000-6512-badd1e130000 pid=4894 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=818383ae-1800-0000-6512-badd1e130000 pid=4894 execve guuid=87f710af-1800-0000-6512-badd21130000 pid=4897 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=87f710af-1800-0000-6512-badd21130000 pid=4897 execve guuid=6e4b9daf-1800-0000-6512-badd24130000 pid=4900 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=6e4b9daf-1800-0000-6512-badd24130000 pid=4900 execve guuid=7d592cb0-1800-0000-6512-badd27130000 pid=4903 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=7d592cb0-1800-0000-6512-badd27130000 pid=4903 execve guuid=c6e1c6b0-1800-0000-6512-badd2c130000 pid=4908 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=c6e1c6b0-1800-0000-6512-badd2c130000 pid=4908 execve guuid=6cec61b1-1800-0000-6512-badd30130000 pid=4912 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=6cec61b1-1800-0000-6512-badd30130000 pid=4912 execve guuid=8e4cc9b1-1800-0000-6512-badd32130000 pid=4914 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=8e4cc9b1-1800-0000-6512-badd32130000 pid=4914 execve guuid=7b4729b2-1800-0000-6512-badd34130000 pid=4916 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=7b4729b2-1800-0000-6512-badd34130000 pid=4916 execve guuid=394b8bb2-1800-0000-6512-badd38130000 pid=4920 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=394b8bb2-1800-0000-6512-badd38130000 pid=4920 execve guuid=7f13ebb2-1800-0000-6512-badd3c130000 pid=4924 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=7f13ebb2-1800-0000-6512-badd3c130000 pid=4924 execve guuid=f0be4db3-1800-0000-6512-badd3f130000 pid=4927 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=f0be4db3-1800-0000-6512-badd3f130000 pid=4927 execve guuid=9168afb3-1800-0000-6512-badd43130000 pid=4931 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=9168afb3-1800-0000-6512-badd43130000 pid=4931 execve guuid=13a912b4-1800-0000-6512-badd47130000 pid=4935 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=13a912b4-1800-0000-6512-badd47130000 pid=4935 execve guuid=214e76b4-1800-0000-6512-badd49130000 pid=4937 /usr/bin/cp guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=214e76b4-1800-0000-6512-badd49130000 pid=4937 execve guuid=757bdab4-1800-0000-6512-badd4b130000 pid=4939 /usr/bin/touch guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=757bdab4-1800-0000-6512-badd4b130000 pid=4939 execve guuid=7dd522b5-1800-0000-6512-badd4f130000 pid=4943 /usr/bin/chmod guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=7dd522b5-1800-0000-6512-badd4f130000 pid=4943 execve guuid=d7ec70b5-1800-0000-6512-badd50130000 pid=4944 /usr/bin/chmod guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=d7ec70b5-1800-0000-6512-badd50130000 pid=4944 execve guuid=e0dbc8b5-1800-0000-6512-badd51130000 pid=4945 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=e0dbc8b5-1800-0000-6512-badd51130000 pid=4945 execve guuid=817735b6-1800-0000-6512-badd52130000 pid=4946 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=817735b6-1800-0000-6512-badd52130000 pid=4946 execve guuid=d2e7acb6-1800-0000-6512-badd55130000 pid=4949 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=d2e7acb6-1800-0000-6512-badd55130000 pid=4949 execve guuid=0770edb6-1800-0000-6512-badd56130000 pid=4950 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=0770edb6-1800-0000-6512-badd56130000 pid=4950 execve guuid=5e982bb7-1800-0000-6512-badd58130000 pid=4952 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=5e982bb7-1800-0000-6512-badd58130000 pid=4952 execve guuid=fd4669b7-1800-0000-6512-badd5a130000 pid=4954 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=fd4669b7-1800-0000-6512-badd5a130000 pid=4954 execve guuid=3487a8b7-1800-0000-6512-badd5c130000 pid=4956 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=3487a8b7-1800-0000-6512-badd5c130000 pid=4956 execve guuid=07b7e5b7-1800-0000-6512-badd5e130000 pid=4958 /usr/bin/chattr guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=07b7e5b7-1800-0000-6512-badd5e130000 pid=4958 execve guuid=3ca824b8-1800-0000-6512-badd5f130000 pid=4959 /usr/bin/bash guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=3ca824b8-1800-0000-6512-badd5f130000 pid=4959 clone guuid=441e29b8-1800-0000-6512-badd61130000 pid=4961 /usr/bin/bash guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=441e29b8-1800-0000-6512-badd61130000 pid=4961 clone guuid=a6e246b8-1800-0000-6512-badd62130000 pid=4962 /usr/bin/curl net guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=a6e246b8-1800-0000-6512-badd62130000 pid=4962 execve guuid=a3214bb8-1800-0000-6512-badd63130000 pid=4963 /usr/bin/dash guuid=9bf505aa-1800-0000-6512-baddf9120000 pid=4857->guuid=a3214bb8-1800-0000-6512-badd63130000 pid=4963 execve 124ee36c-bdbd-5d46-bbb1-b2cd81367f04 160.119.69.4:80 guuid=a6e246b8-1800-0000-6512-badd62130000 pid=4962->124ee36c-bdbd-5d46-bbb1-b2cd81367f04 con
Threat name:
Linux.Backdoor.WebShell
Status:
Malicious
First seen:
2026-07-23 22:33:38 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_Base64_Exec_Apr24
Author:Christian Burkard
Description:Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fe2e5dc794bf4bebe2092e45422fe5f9c5e8083e7ef32b5f9c17018941e19fa1

(this sample)

  
Delivery method
Distributed via web download

Comments