MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03fd0b0dbd4829ab826f8d58c63274ff84075c4bf45f092b32040ec71a30478f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 03fd0b0dbd4829ab826f8d58c63274ff84075c4bf45f092b32040ec71a30478f
SHA3-384 hash: db3d8f5ed620eb9d100d83798cc492b20c803e81357eb934c46db6243e58ec25741383e1c68b12b87919bdc0fbc9a5a6
SHA1 hash: c8e1d956c5865f5cfc19780e2ba9723119c2bd8c
MD5 hash: 1ddb465a9a90da8264aea3161eeaa72b
humanhash: mobile-five-butter-butter
File name:traff
Download: download sample
File size:208 bytes
First seen:2026-08-06 19:36:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:QFKIaM3BFDzCLftN5FaNYLftN5FOaOOdhHNJ+vyIRwC21LaUnnyVtNJx4nudFc0s:QOSB1IdAYdUaZ+TRwC0WvPdAFd
TLSH T1E5D0A9A152312F12AF008B0A327AC9612843398B804A208CF0E4CD545F8884CAAA2B12
Magika shell
Reporter BlinkzSec
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
downloader
Status:
terminated
Behavior Graph:
%3 guuid=d3ac37c3-1b00-0000-0a94-d3946b0a0000 pid=2667 /usr/bin/sudo guuid=0c0bb2c7-1b00-0000-0a94-d394720a0000 pid=2674 /tmp/sample.bin guuid=d3ac37c3-1b00-0000-0a94-d3946b0a0000 pid=2667->guuid=0c0bb2c7-1b00-0000-0a94-d394720a0000 pid=2674 execve guuid=a0beffc7-1b00-0000-0a94-d394740a0000 pid=2676 /usr/bin/curl net send-data write-file guuid=0c0bb2c7-1b00-0000-0a94-d394720a0000 pid=2674->guuid=a0beffc7-1b00-0000-0a94-d394740a0000 pid=2676 execve guuid=ec796ddd-1b00-0000-0a94-d394880a0000 pid=2696 /usr/bin/wget net send-data write-file guuid=0c0bb2c7-1b00-0000-0a94-d394720a0000 pid=2674->guuid=ec796ddd-1b00-0000-0a94-d394880a0000 pid=2696 execve guuid=75bd47ed-1b00-0000-0a94-d3949c0a0000 pid=2716 /usr/bin/chmod guuid=0c0bb2c7-1b00-0000-0a94-d394720a0000 pid=2674->guuid=75bd47ed-1b00-0000-0a94-d3949c0a0000 pid=2716 execve guuid=249baaed-1b00-0000-0a94-d3949e0a0000 pid=2718 /var/tmp/cli write-file zombie guuid=0c0bb2c7-1b00-0000-0a94-d394720a0000 pid=2674->guuid=249baaed-1b00-0000-0a94-d3949e0a0000 pid=2718 execve d362df78-f26c-5d9d-8fb2-3e6aab20268a 94.154.43.103:80 guuid=a0beffc7-1b00-0000-0a94-d394740a0000 pid=2676->d362df78-f26c-5d9d-8fb2-3e6aab20268a send: 80B guuid=ec796ddd-1b00-0000-0a94-d394880a0000 pid=2696->d362df78-f26c-5d9d-8fb2-3e6aab20268a send: 131B guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973 /tmp/fileaIZvBu write-file guuid=249baaed-1b00-0000-0a94-d3949e0a0000 pid=2718->guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973 execve guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2985 /tmp/fileaIZvBu send-data guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973->guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2985 clone guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2986 /tmp/fileaIZvBu guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973->guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2986 clone guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2987 /tmp/fileaIZvBu net send-data guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973->guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2987 clone guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2988 /tmp/fileaIZvBu net send-data guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973->guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2988 clone guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2990 /tmp/fileaIZvBu dns send-data guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2973->guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2990 clone 253ec59a-6bd7-5caa-9cb8-d19ef46b6867 blnc.traffmonetizer.com:443 guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2985->253ec59a-6bd7-5caa-9cb8-d19ef46b6867 send: 509B 04a1286a-7d47-592e-b271-042d033956f7 srv16.traffmonetizer.com:769 guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2985->04a1286a-7d47-592e-b271-042d033956f7 send: 658302B guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2987->04a1286a-7d47-592e-b271-042d033956f7 send: 974B 01ec1863-14bf-5df7-a4cc-54733d644a1f srv16.traffmonetizer.com:80 guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2987->01ec1863-14bf-5df7-a4cc-54733d644a1f con guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2988->253ec59a-6bd7-5caa-9cb8-d19ef46b6867 con guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2988->04a1286a-7d47-592e-b271-042d033956f7 send: 396356B guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2988->01ec1863-14bf-5df7-a4cc-54733d644a1f send: 111B f8fc4da8-f142-5066-a980-ccf85c6787cc srv16.traffmonetizer.com:711 guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2988->f8fc4da8-f142-5066-a980-ccf85c6787cc send: 4B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=adb76487-1c00-0000-0a94-d3949d0b0000 pid=2990->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 166B
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 03fd0b0dbd4829ab826f8d58c63274ff84075c4bf45f092b32040ec71a30478f

(this sample)

  
Delivery method
Distributed via web download

Comments