6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207
Classification: Malicious
6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207 is a malicious file sample. Linked to Teamtnt activity. Detected by 35 antivirus engines.
Detection summary
- 35 antivirus detections
- 0 IDS alerts
- 64 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: TEAMTNT (G0139)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Teamtnt | Triage | 2026-06-26 08:37:27 | 2026-06-26 08:37:27 | malicious-activity | G0139 TeamTNT |
| Generic Malware | Hybrid-Analysis | 2025-04-21 08:45:05 | 2025-04-21 10:00:26 |
Tags
teamtnt team_tnt antivm apt defense_evasion discovery linux loaderSample information
- Filenames
- 6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207
- File type
- Bourne-Again shell script, ASCII text executable, ...
- Size
- 9665 bytes
- MD5
c491a19742c352b2c6221037dfac7a4a- SHA-1
7a0bf738469861712184b08c1a985099415e2a9c- SHA-256
6075906fbc8898515fe09a046d81ca66429c9b3052a13d6b3ca6f8294c70d207- First indexed
- 2025-04-21 08:33:08
- Last updated
- 2026-07-21 18:53:33
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Downloader.Shell.Agent |
| AVG | BV:Agent-BLR [Drp] |
| AhnLab-V3 | Trojan/Script.TeamTNT |
| Antiy-AVL | Trojan/Shell.Teamtnt |
| Arcabit | Trojan.Linux.Generic.D3549F |
| Avast | BV:Agent-BLR [Drp] |
| Avira | TR/Special.CK |
| BitDefender | Trojan.Linux.Generic.218271 |
| CAT-QuickHeal | Script.Trojan.44788 |
| ClamAV | Unix.Infostealer.TeamTNT-9940825-0 |
| Cynet | Malicious (score: 99) |
| DrWeb | Linux.TeamTNT.87 |
| ESET-NOD32 | Linux/YellowDye.Q |
| Emsisoft | Trojan.Linux.Generic.218271 (B) |
| F-Secure | Trojan.TR/Special.CK |
| FireEye | Trojan.Linux.Generic.218271 |
| GData | Trojan.Linux.Generic.218271 |
| Detected | |
| Ikarus | Trojan.Linux.Yellowdye |
| Kaspersky | HEUR:Trojan.Shell.Agent.ax |
| Lionic | Trojan.Shell.AwfulShred.4!c |
| MAX | malware (ai score=94) |
| McAfee | PS/Agent.ez |
| McAfee-GW-Edition | PS/Agent.ez |
| MicroWorld-eScan | Trojan.Linux.Generic.218271 |
| Microsoft | Trojan:Win32/Vigorf.A |
| Rising | Trojan.YellowDye!8.12727 (TOPIS:E0:EEyuoacy8IC) |
| Sangfor | Malware.ELF-Script.Save.ec7de1c7 |
| Sophos | Linux/Miner-ACR |
| Symantec | Hacktool |
| Tencent | Win32.Trojan.Agent.Mgil |
| TrendMicro | TrojanSpy.SH.CHIMAERA.AA |
| TrendMicro-HouseCall | TrojanSpy.SH.CHIMAERA.AA |
| VIPRE | Trojan.Linux.Generic.218271 |
| ZoneAlarm | HEUR:Trojan.Shell.Agent.ax |
Process list
| Name | Command line |
|---|---|
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |
| bash | bash /home/ubuntu/6075906fbc88207 |