🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 163a8f4faf9361239e3ef1a5ddfaa28ff48afd5b9c5b4c17ffd92fa5c40b99e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 163a8f4faf9361239e3ef1a5ddfaa28ff48afd5b9c5b4c17ffd92fa5c40b99e6
SHA3-384 hash: b60063571734e98c2022ef880c95e2909d9e62355aa53cacc0f57659f71d5f9dbb8aa7d68999128edf94a6ad6f092309
SHA1 hash: 311dbde51bacc51c007804ce931a3f7dfdf6f06c
MD5 hash: 01a4a972fea2c3b137aac0b7661ad8fa
humanhash: montana-zebra-fillet-burger
File name:s
Download: download sample
File size:345 bytes
First seen:2026-09-18 04:45:31 UTC
Last seen:2026-09-18 14:18:48 UTC
File type: sh
MIME type:text/plain
ssdeep 6:ebAAj73w5/KiYEGvwW2AVFhGq4XXQZrKGy3D2QZrKGygt9Mepn:7AWKZHY4uqDZrKGyT3ZrKGygt9MW
TLSH T1DDE020CE64D0CD7038454DFBB061490594CBD8CD1AA24FC456D8107F594ED08B293F12
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://195.178.110.204/armv7l77b0b59d2733125c03a25e10bdd7b1b5629cbf80b8627c9aec61b07164d984d0 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
21
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
ps1
First seen:
2026-09-18T02:25:00Z UTC
Last seen:
2026-09-20T00:35:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=982594ce-1700-0000-85b9-ac6c730d0000 pid=3443 /usr/bin/sudo guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453 /tmp/sample.bin guuid=982594ce-1700-0000-85b9-ac6c730d0000 pid=3443->guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453 execve guuid=f676f0d2-1700-0000-85b9-ac6c7e0d0000 pid=3454 /usr/bin/dash guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=f676f0d2-1700-0000-85b9-ac6c7e0d0000 pid=3454 clone guuid=b5b5c4d4-1700-0000-85b9-ac6c870d0000 pid=3463 /usr/bin/rm delete-file guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=b5b5c4d4-1700-0000-85b9-ac6c870d0000 pid=3463 execve guuid=2fed75d5-1700-0000-85b9-ac6c890d0000 pid=3465 /usr/bin/rm delete-file guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=2fed75d5-1700-0000-85b9-ac6c890d0000 pid=3465 execve guuid=e701e9d5-1700-0000-85b9-ac6c8c0d0000 pid=3468 /usr/bin/rm delete-file guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=e701e9d5-1700-0000-85b9-ac6c8c0d0000 pid=3468 execve guuid=d82f51d6-1700-0000-85b9-ac6c8d0d0000 pid=3469 /usr/bin/dash guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=d82f51d6-1700-0000-85b9-ac6c8d0d0000 pid=3469 clone guuid=c8e4cddf-1700-0000-85b9-ac6c9f0d0000 pid=3487 /usr/bin/chmod guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=c8e4cddf-1700-0000-85b9-ac6c9f0d0000 pid=3487 execve guuid=3f3fdee0-1700-0000-85b9-ac6ca10d0000 pid=3489 /usr/bin/dash guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=3f3fdee0-1700-0000-85b9-ac6ca10d0000 pid=3489 clone guuid=c5f441e3-1700-0000-85b9-ac6ca60d0000 pid=3494 /usr/bin/rm delete-file guuid=8f459fd2-1700-0000-85b9-ac6c7d0d0000 pid=3453->guuid=c5f441e3-1700-0000-85b9-ac6ca60d0000 pid=3494 execve guuid=32eef9d2-1700-0000-85b9-ac6c7f0d0000 pid=3455 /usr/bin/cat guuid=f676f0d2-1700-0000-85b9-ac6c7e0d0000 pid=3454->guuid=32eef9d2-1700-0000-85b9-ac6c7f0d0000 pid=3455 execve guuid=646f09d3-1700-0000-85b9-ac6c810d0000 pid=3457 /usr/bin/grep guuid=f676f0d2-1700-0000-85b9-ac6c7e0d0000 pid=3454->guuid=646f09d3-1700-0000-85b9-ac6c810d0000 pid=3457 execve guuid=237b11d3-1700-0000-85b9-ac6c820d0000 pid=3458 /usr/bin/grep guuid=f676f0d2-1700-0000-85b9-ac6c7e0d0000 pid=3454->guuid=237b11d3-1700-0000-85b9-ac6c820d0000 pid=3458 execve guuid=95f917d3-1700-0000-85b9-ac6c830d0000 pid=3459 /usr/bin/cut guuid=f676f0d2-1700-0000-85b9-ac6c7e0d0000 pid=3454->guuid=95f917d3-1700-0000-85b9-ac6c830d0000 pid=3459 execve guuid=0b7669d6-1700-0000-85b9-ac6c8e0d0000 pid=3470 /usr/bin/wget net send-data write-file guuid=d82f51d6-1700-0000-85b9-ac6c8d0d0000 pid=3469->guuid=0b7669d6-1700-0000-85b9-ac6c8e0d0000 pid=3470 execve 0d6a8e00-ec4e-588b-8e02-8670607dfe9b 195.178.110.204:80 guuid=0b7669d6-1700-0000-85b9-ac6c8e0d0000 pid=3470->0d6a8e00-ec4e-588b-8e02-8670607dfe9b send: 136B
Threat name:
Script-Shell.Trojan.MiraiB
Status:
Malicious
First seen:
2026-09-18 05:15:52 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:LIN_Downloader_Unknown_WgetChmodExecute
Author:Marjoriefort
Description:Script shell downloader : wget+curl, chmod 777, execution, effacement (rm -rf) - botnet style
Reference:misses_archive / grappe 5.182.210.174

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 163a8f4faf9361239e3ef1a5ddfaa28ff48afd5b9c5b4c17ffd92fa5c40b99e6

(this sample)

  
Delivery method
Distributed via web download

Comments