MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1752db4051fb047a2fc8eb9ae4bb1aaa7636acf67bf26e67b34e71f6ced08ac9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 1752db4051fb047a2fc8eb9ae4bb1aaa7636acf67bf26e67b34e71f6ced08ac9
SHA3-384 hash: 34d709b7045b2a588bcb1a964cae1250c276e1df49c30fc2c8ecaa568fda05ad24e7a3f95beac700b93c4e8488ef91f4
SHA1 hash: e1cb26f752fe48863022f4482f2eb67b82f6b8d8
MD5 hash: 5e1e285841e803b017b0a4e8ff768eed
humanhash: artist-lima-nevada-coffee
File name:rev.sh
Download: download sample
File size:1'167 bytes
First seen:2026-08-13 07:49:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:w1NLde/sjsAMr+SrNvNSL5lOKVh0TGz5lOKVh0TGP:wT5FgZ6SuOKr0TGGKr0TGP
TLSH T1C1219AB2A2F16D753F7084686106D23036DA2B42CF9C5DF2583C9AA23A135D4E094F12
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash evasive lolbin
Status:
terminated
Behavior Graph:
%3 guuid=bad8d6c4-1700-0000-55be-28ef830b0000 pid=2947 /usr/bin/sudo guuid=d74b1dc7-1700-0000-55be-28ef8c0b0000 pid=2956 /tmp/sample.bin guuid=bad8d6c4-1700-0000-55be-28ef830b0000 pid=2947->guuid=d74b1dc7-1700-0000-55be-28ef8c0b0000 pid=2956 execve guuid=d9f0a3c7-1700-0000-55be-28ef8e0b0000 pid=2958 /usr/bin/bash net guuid=d74b1dc7-1700-0000-55be-28ef8c0b0000 pid=2956->guuid=d9f0a3c7-1700-0000-55be-28ef8e0b0000 pid=2958 clone guuid=f351a5cc-1700-0000-55be-28ef9b0b0000 pid=2971 /usr/bin/bash net guuid=d74b1dc7-1700-0000-55be-28ef8c0b0000 pid=2956->guuid=f351a5cc-1700-0000-55be-28ef9b0b0000 pid=2971 clone guuid=e76fa0d1-1700-0000-55be-28efa30b0000 pid=2979 /usr/bin/perl net guuid=d74b1dc7-1700-0000-55be-28ef8c0b0000 pid=2956->guuid=e76fa0d1-1700-0000-55be-28efa30b0000 pid=2979 execve guuid=1e67bfdc-1700-0000-55be-28efba0b0000 pid=3002 /usr/bin/python3.11 net guuid=d74b1dc7-1700-0000-55be-28ef8c0b0000 pid=2956->guuid=1e67bfdc-1700-0000-55be-28efba0b0000 pid=3002 execve 9f437342-52d6-5c24-b99d-1346789026b6 165.22.2.14:5656 guuid=d9f0a3c7-1700-0000-55be-28ef8e0b0000 pid=2958->9f437342-52d6-5c24-b99d-1346789026b6 con guuid=f351a5cc-1700-0000-55be-28ef9b0b0000 pid=2971->9f437342-52d6-5c24-b99d-1346789026b6 con guuid=e76fa0d1-1700-0000-55be-28efa30b0000 pid=2979->9f437342-52d6-5c24-b99d-1346789026b6 con guuid=1e67bfdc-1700-0000-55be-28efba0b0000 pid=3002->9f437342-52d6-5c24-b99d-1346789026b6 con
Threat name:
Script-Python.Trojan.ReverseShell
Status:
Malicious
First seen:
2026-08-13 07:50:45 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_shellpop_Bash
Author:Tobias Michalski
Description:Detects susupicious bash command
Reference:https://github.com/0x00-0x00/ShellPop

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1752db4051fb047a2fc8eb9ae4bb1aaa7636acf67bf26e67b34e71f6ced08ac9

(this sample)

  
Delivery method
Distributed via web download

Comments