MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0076fe37f41ee52f12cf76c5bbbc5eb726ce534ec6da22c358499bb948d17b6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tsunami


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 0076fe37f41ee52f12cf76c5bbbc5eb726ce534ec6da22c358499bb948d17b6c
SHA3-384 hash: 6157430bc8501acb2061335e506fe667ac879772861feb6b636962f63063edfc0737b6cf21438bfe8793e78e9a0da2d6
SHA1 hash: 7eabae4200118c4e89979658db6e4d905fe3dae9
MD5 hash: cf70ee36f1e9247f2146e4981924d4f4
humanhash: november-magnesium-arizona-rugby
File name:pay.sh
Download: download sample
Signature Tsunami
File size:3'313 bytes
First seen:2024-10-22 16:05:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:7NyNy2INyPyRp7y11tyhycyQAFCp7yr1ty25:7NA+NGeZ28HXAFCZcv
TLSH T14F614899B3DD867548F5F0B21A3E994C222962E2421D5DCDB6EB6CFF244E9C4E3081D3
Magika shell
Reporter abuse_ch
Tags:sh Tsunami

Intelligence


File Origin
# of uploads :
1
# of downloads :
100
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
Shell
Result
Verdict:
MALICIOUS
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2024-10-21 03:54:29 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt family:kaiten antivm botnet defense_evasion discovery linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Modifies Bash startup script
Creates/modifies environment variables
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Detects Kaiten/Tsunami Payload
Gafgyt/Bashlite
Kaiten/Tsunami
Malware Config
C2 Extraction:
104.234.24.138:1990
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Tsunami

sh 0076fe37f41ee52f12cf76c5bbbc5eb726ce534ec6da22c358499bb948d17b6c

(this sample)

  
Delivery method
Distributed via web download

Comments