MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 049f300e4ff0f302f770fade35b547dd8ec8ad1e1ef44f2bb879dae917cd2dfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 049f300e4ff0f302f770fade35b547dd8ec8ad1e1ef44f2bb879dae917cd2dfb
SHA3-384 hash: 572f4bb9e8c89cd9a75f7911f8445cb87d256173fafa11096a6c5e6c5a6feab699946ebef6774132a009892acc2f3d10
SHA1 hash: de30c096850f9eb048514265e72dc893fee4c845
MD5 hash: ad52f8863d9d45a44eca0b89f0a0520f
humanhash: venus-river-lithium-zebra
File name:oldercheck.sh
Download: download sample
File size:627 bytes
First seen:2026-08-06 19:36:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:geKc6VSCom0vUiRoy1v0QOnrMziaXuaqRHwntawSD/rgVHxJNxhIJlztHKw:g260mOD+nl72tg8rrIJLHt
TLSH T187F0249307267F7C388335D0E06A4091A2A5A24951FB6A706184AFFAB449044D7BDE31
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://94.26.106.195/syst3mddcf343df280816c4856ee164b9b4b14906a09b1fd4bfab604ee9370529ed61d1 Mirai94-26-106-195 elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=b08de67a-1b00-0000-e9d4-938d78090000 pid=2424 /usr/bin/sudo guuid=f0b77a7e-1b00-0000-e9d4-938d81090000 pid=2433 /tmp/sample.bin guuid=b08de67a-1b00-0000-e9d4-938d78090000 pid=2424->guuid=f0b77a7e-1b00-0000-e9d4-938d81090000 pid=2433 execve guuid=8e59197f-1b00-0000-e9d4-938d83090000 pid=2435 /usr/bin/flock guuid=f0b77a7e-1b00-0000-e9d4-938d81090000 pid=2433->guuid=8e59197f-1b00-0000-e9d4-938d83090000 pid=2435 execve guuid=04000e80-1b00-0000-e9d4-938d86090000 pid=2438 /usr/bin/bash guuid=8e59197f-1b00-0000-e9d4-938d83090000 pid=2435->guuid=04000e80-1b00-0000-e9d4-938d86090000 pid=2438 execve guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441 /usr/bin/bash zombie guuid=04000e80-1b00-0000-e9d4-938d86090000 pid=2438->guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441 execve guuid=26cd2683-1b00-0000-e9d4-938d8d090000 pid=2445 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=26cd2683-1b00-0000-e9d4-938d8d090000 pid=2445 execve guuid=bf47ba91-1b00-0000-e9d4-938dad090000 pid=2477 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=bf47ba91-1b00-0000-e9d4-938dad090000 pid=2477 execve guuid=27e0139c-1b00-0000-e9d4-938dc5090000 pid=2501 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=27e0139c-1b00-0000-e9d4-938dc5090000 pid=2501 execve guuid=f37320a3-1b00-0000-e9d4-938ddb090000 pid=2523 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=f37320a3-1b00-0000-e9d4-938ddb090000 pid=2523 execve guuid=273999a5-1b00-0000-e9d4-938de2090000 pid=2530 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=273999a5-1b00-0000-e9d4-938de2090000 pid=2530 execve guuid=9cb3e5a7-1b00-0000-e9d4-938de5090000 pid=2533 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=9cb3e5a7-1b00-0000-e9d4-938de5090000 pid=2533 execve guuid=3d1d42aa-1b00-0000-e9d4-938de7090000 pid=2535 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=3d1d42aa-1b00-0000-e9d4-938de7090000 pid=2535 execve guuid=bd1fa6ac-1b00-0000-e9d4-938dec090000 pid=2540 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=bd1fa6ac-1b00-0000-e9d4-938dec090000 pid=2540 execve guuid=d1e002af-1b00-0000-e9d4-938df1090000 pid=2545 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=d1e002af-1b00-0000-e9d4-938df1090000 pid=2545 execve guuid=85203db2-1b00-0000-e9d4-938df9090000 pid=2553 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=85203db2-1b00-0000-e9d4-938df9090000 pid=2553 execve guuid=655466b9-1b00-0000-e9d4-938d0e0a0000 pid=2574 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=655466b9-1b00-0000-e9d4-938d0e0a0000 pid=2574 execve guuid=a62fffc4-1b00-0000-e9d4-938d2e0a0000 pid=2606 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=a62fffc4-1b00-0000-e9d4-938d2e0a0000 pid=2606 execve guuid=9b83bcd0-1b00-0000-e9d4-938d400a0000 pid=2624 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=9b83bcd0-1b00-0000-e9d4-938d400a0000 pid=2624 execve guuid=417afcd9-1b00-0000-e9d4-938d4c0a0000 pid=2636 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=417afcd9-1b00-0000-e9d4-938d4c0a0000 pid=2636 execve guuid=5c1b91df-1b00-0000-e9d4-938d540a0000 pid=2644 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=5c1b91df-1b00-0000-e9d4-938d540a0000 pid=2644 execve guuid=dce689e6-1b00-0000-e9d4-938d5c0a0000 pid=2652 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=dce689e6-1b00-0000-e9d4-938d5c0a0000 pid=2652 execve guuid=5d7fd3ea-1b00-0000-e9d4-938d630a0000 pid=2659 /usr/bin/pgrep guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=5d7fd3ea-1b00-0000-e9d4-938d630a0000 pid=2659 execve guuid=505cd5ed-1b00-0000-e9d4-938d6a0a0000 pid=2666 /usr/bin/bash guuid=729e0582-1b00-0000-e9d4-938d89090000 pid=2441->guuid=505cd5ed-1b00-0000-e9d4-938d6a0a0000 pid=2666 clone guuid=2336e2ed-1b00-0000-e9d4-938d6b0a0000 pid=2667 /usr/bin/wget guuid=505cd5ed-1b00-0000-e9d4-938d6a0a0000 pid=2666->guuid=2336e2ed-1b00-0000-e9d4-938d6b0a0000 pid=2667 execve
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2026-04-25 04:43:00 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

sh 049f300e4ff0f302f770fade35b547dd8ec8ad1e1ef44f2bb879dae917cd2dfb

(this sample)

Comments