MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 049f300e4ff0f302f770fade35b547dd8ec8ad1e1ef44f2bb879dae917cd2dfb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 049f300e4ff0f302f770fade35b547dd8ec8ad1e1ef44f2bb879dae917cd2dfb |
|---|---|
| SHA3-384 hash: | 572f4bb9e8c89cd9a75f7911f8445cb87d256173fafa11096a6c5e6c5a6feab699946ebef6774132a009892acc2f3d10 |
| SHA1 hash: | de30c096850f9eb048514265e72dc893fee4c845 |
| MD5 hash: | ad52f8863d9d45a44eca0b89f0a0520f |
| humanhash: | venus-river-lithium-zebra |
| File name: | oldercheck.sh |
| Download: | download sample |
| File size: | 627 bytes |
| First seen: | 2026-08-06 19:36:40 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/plain |
| ssdeep | 12:geKc6VSCom0vUiRoy1v0QOnrMziaXuaqRHwntawSD/rgVHxJNxhIJlztHKw:g260mOD+nl72tg8rrIJLHt |
| TLSH | T187F0249307267F7C388335D0E06A4091A2A5A24951FB6A706184AFFAB449044D7BDE31 |
| Magika | shell |
| Reporter |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://94.26.106.195/syst3md | dcf343df280816c4856ee164b9b4b14906a09b1fd4bfab604ee9370529ed61d1 | Mirai | 94-26-106-195 elf mirai |
Intelligence
File Origin
# of uploads :
1
# of downloads :
51
Origin country :
CHVendor Threat Intelligence
No detections
Verdict:
Unknown
File Type:
text
Status:
terminated
Behavior Graph:
Score:
74%
Verdict:
Malware
File Type:
SCRIPT
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2026-04-25 04:43:00 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
2/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
sh 049f300e4ff0f302f770fade35b547dd8ec8ad1e1ef44f2bb879dae917cd2dfb
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.