MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b409b5e11163b4e738a069f8a97da205c63a1ef18c7a97ce9110bc4aea83a9c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b409b5e11163b4e738a069f8a97da205c63a1ef18c7a97ce9110bc4aea83a9c3
SHA3-384 hash: c6d8d0f7e1706c7ffe278a421f668141355c08692f746c3693d10a3447b8fe7f94a0aa02a420d1647227319af1144219
SHA1 hash: b61ce45d52e3f1841af1d183381643564aee2d3a
MD5 hash: 3b8b01d0e076eab48f6f156b4266b85d
humanhash: six-lion-romeo-lactose
File name:microc2.sh
Download: download sample
File size:2'107 bytes
First seen:2026-05-02 21:14:07 UTC
Last seen:2026-05-02 21:14:18 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vFA5158Na+rEurDU1DhE4KZXYe+Ku34vkRCM:dAq/rU8Ye+FgM
TLSH T1164179E2F878D9A3B65B003AF59C72502AC3493E4564B596708F2CD0277ED6DB42E239
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
URLMalware sample (SHA256 hash)SignatureTags
http://217.60.245.90/bins/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
38
Origin country :
NL NL
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-01T15:39:00Z UTC
Last seen:
2026-05-03T03:22:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=16178d90-1700-0000-7f33-f1fcd10a0000 pid=2769 /usr/bin/sudo guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775 /tmp/sample.bin write-config guuid=16178d90-1700-0000-7f33-f1fcd10a0000 pid=2769->guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775 execve guuid=4e2d9793-1700-0000-7f33-f1fcd90a0000 pid=2777 /usr/bin/uname guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=4e2d9793-1700-0000-7f33-f1fcd90a0000 pid=2777 execve guuid=7b3ee393-1700-0000-7f33-f1fcdb0a0000 pid=2779 /usr/bin/wget net send-data write-file guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=7b3ee393-1700-0000-7f33-f1fcdb0a0000 pid=2779 execve guuid=81e36599-1700-0000-7f33-f1fce40a0000 pid=2788 /usr/bin/chmod guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=81e36599-1700-0000-7f33-f1fce40a0000 pid=2788 execve guuid=61d4ae99-1700-0000-7f33-f1fce60a0000 pid=2790 /usr/bin/cp guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=61d4ae99-1700-0000-7f33-f1fce60a0000 pid=2790 execve guuid=2ef70b9a-1700-0000-7f33-f1fce80a0000 pid=2792 /usr/bin/chmod guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=2ef70b9a-1700-0000-7f33-f1fce80a0000 pid=2792 execve guuid=1cc5559a-1700-0000-7f33-f1fcea0a0000 pid=2794 /usr/bin/dash guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=1cc5559a-1700-0000-7f33-f1fcea0a0000 pid=2794 clone guuid=c267c89a-1700-0000-7f33-f1fced0a0000 pid=2797 /usr/bin/dash guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=c267c89a-1700-0000-7f33-f1fced0a0000 pid=2797 clone guuid=a9c6ce9a-1700-0000-7f33-f1fcee0a0000 pid=2798 /usr/bin/dash guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=a9c6ce9a-1700-0000-7f33-f1fcee0a0000 pid=2798 clone guuid=3497ea9a-1700-0000-7f33-f1fcf00a0000 pid=2800 /usr/bin/chmod guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=3497ea9a-1700-0000-7f33-f1fcf00a0000 pid=2800 execve guuid=dfcb299b-1700-0000-7f33-f1fcf10a0000 pid=2801 /usr/bin/cat write-config guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=dfcb299b-1700-0000-7f33-f1fcf10a0000 pid=2801 execve guuid=b1d47c9b-1700-0000-7f33-f1fcf30a0000 pid=2803 /usr/bin/chmod guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=b1d47c9b-1700-0000-7f33-f1fcf30a0000 pid=2803 execve guuid=089dbc9b-1700-0000-7f33-f1fcf50a0000 pid=2805 /usr/sbin/update-rc.d guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=089dbc9b-1700-0000-7f33-f1fcf50a0000 pid=2805 execve guuid=c720e4d6-1700-0000-7f33-f1fc8b0b0000 pid=2955 /tmp/micro.x86_64 mprotect-exec net zombie guuid=9d255c93-1700-0000-7f33-f1fcd70a0000 pid=2775->guuid=c720e4d6-1700-0000-7f33-f1fc8b0b0000 pid=2955 execve b0548038-abb1-5762-a977-813c33ba1383 217.60.245.90:80 guuid=7b3ee393-1700-0000-7f33-f1fcdb0a0000 pid=2779->b0548038-abb1-5762-a977-813c33ba1383 send: 145B guuid=7450629a-1700-0000-7f33-f1fceb0a0000 pid=2795 /usr/bin/dash guuid=1cc5559a-1700-0000-7f33-f1fcea0a0000 pid=2794->guuid=7450629a-1700-0000-7f33-f1fceb0a0000 pid=2795 clone guuid=86ec679a-1700-0000-7f33-f1fcec0a0000 pid=2796 /usr/bin/grep guuid=1cc5559a-1700-0000-7f33-f1fcea0a0000 pid=2794->guuid=86ec679a-1700-0000-7f33-f1fcec0a0000 pid=2796 execve guuid=821ccf9f-1700-0000-7f33-f1fcfa0a0000 pid=2810 /usr/bin/systemctl guuid=089dbc9b-1700-0000-7f33-f1fcf50a0000 pid=2805->guuid=821ccf9f-1700-0000-7f33-f1fcfa0a0000 pid=2810 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c720e4d6-1700-0000-7f33-f1fc8b0b0000 pid=2955->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments