MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0dcf74772dd074dfe0debf03ece61b81e29d5a6e2778d6f9cd80a12e4d4f0a91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0dcf74772dd074dfe0debf03ece61b81e29d5a6e2778d6f9cd80a12e4d4f0a91
SHA3-384 hash: ef81c1c42b3171a74fb371b8443613c94259cb99e1f388b85c2ac3d22e68480a0fc0d63e3f90a40de697175bdc400633
SHA1 hash: 56426222662077bb9353d87ac1e0553e8950a3f6
MD5 hash: 110f76d622ded8035b6c854065e916e4
humanhash: nebraska-batman-eight-hawaii
File name:main_mips
Download: download sample
File size:395 bytes
First seen:2026-08-10 05:29:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:higjkTFfFFuJ6XVf6gdlCtuiMIlRr6+wFkREuNFPE0X9C2FZN9olBCqAVFgpQ:ASkBFFrd6gdlCIiFu+wFk+W8SlF/HjgC
TLSH T129E061D3F860E621F5CDD03D5259659481C3086B2374BEF1F0435E704D1C1453C6E7A0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.191.242.92/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=23e5d9f5-1600-0000-cb6f-2dbe7a0d0000 pid=3450 /usr/bin/sudo guuid=d02e51f8-1600-0000-cb6f-2dbe820d0000 pid=3458 /tmp/sample.bin guuid=23e5d9f5-1600-0000-cb6f-2dbe7a0d0000 pid=3450->guuid=d02e51f8-1600-0000-cb6f-2dbe820d0000 pid=3458 execve guuid=6bf0f1f8-1600-0000-cb6f-2dbe850d0000 pid=3461 /usr/bin/uname guuid=d02e51f8-1600-0000-cb6f-2dbe820d0000 pid=3458->guuid=6bf0f1f8-1600-0000-cb6f-2dbe850d0000 pid=3461 execve guuid=470e91f9-1600-0000-cb6f-2dbe870d0000 pid=3463 /usr/bin/wget net send-data write-file guuid=d02e51f8-1600-0000-cb6f-2dbe820d0000 pid=3458->guuid=470e91f9-1600-0000-cb6f-2dbe870d0000 pid=3463 execve 5d1d988f-b680-5eab-9afc-a546775bdf2b 160.191.242.92:80 guuid=470e91f9-1600-0000-cb6f-2dbe870d0000 pid=3463->5d1d988f-b680-5eab-9afc-a546775bdf2b send: 135B
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Creates a desktop entry file
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Deletes log files
Modifies init.d
Modifies rc script
Modifies systemd
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Traces itself
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0dcf74772dd074dfe0debf03ece61b81e29d5a6e2778d6f9cd80a12e4d4f0a91

(this sample)

  
Delivery method
Distributed via web download

Comments