MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0791f456de3f04a13cef7ab34156edee9bea3736087fc047513973d29eecac7c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0791f456de3f04a13cef7ab34156edee9bea3736087fc047513973d29eecac7c
SHA3-384 hash: 75aeabed568efc03c0dcb2622eab122eb47507dd9d1b43c84f8a61787b4377afd7f1c4b450917373cbd3079083bcc344
SHA1 hash: 70f18f58df3ebdccf9fcadaab5625ff1052cbf04
MD5 hash: 5ec5596e606e28f8e412414a5276f6e8
humanhash: kentucky-autumn-magnesium-johnny
File name:test.sh
Download: download sample
File size:123 bytes
First seen:2026-08-03 13:45:15 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH/vzg3LcLVc/tvvjYuRebM3PjIWFW3lw2NNin:AzGc+/3RrjrFWwb
TLSH T160B02BE720061C00EFC8985974610170042378B304040AC8101700A43C282C0372A110
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=e1c230de-1800-0000-8b52-1b87860a0000 pid=2694 /usr/bin/sudo guuid=fa675be0-1800-0000-8b52-1b87870a0000 pid=2695 /tmp/sample.bin guuid=e1c230de-1800-0000-8b52-1b87860a0000 pid=2694->guuid=fa675be0-1800-0000-8b52-1b87870a0000 pid=2695 execve guuid=112c01e1-1800-0000-8b52-1b87890a0000 pid=2697 /usr/bin/curl net guuid=fa675be0-1800-0000-8b52-1b87870a0000 pid=2695->guuid=112c01e1-1800-0000-8b52-1b87890a0000 pid=2697 execve e976bf79-fb8d-550d-a1fe-adb4c9a8e850 77.0.42.76:8000 guuid=112c01e1-1800-0000-8b52-1b87890a0000 pid=2697->e976bf79-fb8d-550d-a1fe-adb4c9a8e850 con
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0791f456de3f04a13cef7ab34156edee9bea3736087fc047513973d29eecac7c

(this sample)

  
Delivery method
Distributed via web download

Comments