🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2042cec85dbb0eb071d5922b0f8604df3c8493affc173ce401bcb0c46e2b4d1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 2042cec85dbb0eb071d5922b0f8604df3c8493affc173ce401bcb0c46e2b4d1f
SHA3-384 hash: 56bc1231c3253b50986ef4ed6575e027906d1639c56e7b6e161eba791a0da1dbb91813d305b4621c1b682853e3dd94d2
SHA1 hash: 4ec341cf453cf87e4cfe96a5010f85e9b8109531
MD5 hash: fde2e430e137341fff24cb25bd902e7c
humanhash: eighteen-freddie-quiet-thirteen
File name:s
Download: download sample
File size:345 bytes
First seen:2026-09-17 11:17:41 UTC
Last seen:2026-09-17 11:23:39 UTC
File type: sh
MIME type:text/plain
ssdeep 6:ebAAj73w5/KiYEGvwW2AVFhGq4XXQZrK4D2QZrKlt9Mepn:7AWKZHY4uqDZrK23ZrKlt9MW
TLSH T1EEE026CE9490CD7038464DFBB0619906A497E8CD1AA20FC8A6D8207F698DE08B293F16
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
4
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=fb8da105-1a00-0000-56ec-1a59db0b0000 pid=3035 /usr/bin/sudo guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041 /tmp/sample.bin guuid=fb8da105-1a00-0000-56ec-1a59db0b0000 pid=3035->guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041 execve guuid=deca310d-1a00-0000-56ec-1a59e40b0000 pid=3044 /usr/bin/dash guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=deca310d-1a00-0000-56ec-1a59e40b0000 pid=3044 clone guuid=88e0cb0f-1a00-0000-56ec-1a59ec0b0000 pid=3052 /usr/bin/rm delete-file guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=88e0cb0f-1a00-0000-56ec-1a59ec0b0000 pid=3052 execve guuid=70a22b10-1a00-0000-56ec-1a59ed0b0000 pid=3053 /usr/bin/rm delete-file guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=70a22b10-1a00-0000-56ec-1a59ed0b0000 pid=3053 execve guuid=bdaf8710-1a00-0000-56ec-1a59ef0b0000 pid=3055 /usr/bin/rm delete-file guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=bdaf8710-1a00-0000-56ec-1a59ef0b0000 pid=3055 execve guuid=6b82ef10-1a00-0000-56ec-1a59f00b0000 pid=3056 /usr/bin/dash guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=6b82ef10-1a00-0000-56ec-1a59f00b0000 pid=3056 clone guuid=fa686819-1a00-0000-56ec-1a59fa0b0000 pid=3066 /usr/bin/chmod guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=fa686819-1a00-0000-56ec-1a59fa0b0000 pid=3066 execve guuid=345ac519-1a00-0000-56ec-1a59fc0b0000 pid=3068 /usr/bin/dash guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=345ac519-1a00-0000-56ec-1a59fc0b0000 pid=3068 clone guuid=fe99831a-1a00-0000-56ec-1a59000c0000 pid=3072 /usr/bin/rm delete-file guuid=7b8e360c-1a00-0000-56ec-1a59e10b0000 pid=3041->guuid=fe99831a-1a00-0000-56ec-1a59000c0000 pid=3072 execve guuid=ae796a0d-1a00-0000-56ec-1a59e50b0000 pid=3045 /usr/bin/cat guuid=deca310d-1a00-0000-56ec-1a59e40b0000 pid=3044->guuid=ae796a0d-1a00-0000-56ec-1a59e50b0000 pid=3045 execve guuid=e09caf0d-1a00-0000-56ec-1a59e70b0000 pid=3047 /usr/bin/grep guuid=deca310d-1a00-0000-56ec-1a59e40b0000 pid=3044->guuid=e09caf0d-1a00-0000-56ec-1a59e70b0000 pid=3047 execve guuid=8d30c10d-1a00-0000-56ec-1a59e80b0000 pid=3048 /usr/bin/grep guuid=deca310d-1a00-0000-56ec-1a59e40b0000 pid=3044->guuid=8d30c10d-1a00-0000-56ec-1a59e80b0000 pid=3048 execve guuid=7f93df0d-1a00-0000-56ec-1a59e90b0000 pid=3049 /usr/bin/cut guuid=deca310d-1a00-0000-56ec-1a59e40b0000 pid=3044->guuid=7f93df0d-1a00-0000-56ec-1a59e90b0000 pid=3049 execve guuid=1130fc10-1a00-0000-56ec-1a59f10b0000 pid=3057 /usr/bin/wget net send-data write-file guuid=6b82ef10-1a00-0000-56ec-1a59f00b0000 pid=3056->guuid=1130fc10-1a00-0000-56ec-1a59f10b0000 pid=3057 execve 0d6a8e00-ec4e-588b-8e02-8670607dfe9b 195.178.110.204:80 guuid=1130fc10-1a00-0000-56ec-1a59f10b0000 pid=3057->0d6a8e00-ec4e-588b-8e02-8670607dfe9b send: 136B
Threat name:
Script-Shell.Trojan.MiraiB
Status:
Malicious
First seen:
2026-09-17 11:25:32 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2042cec85dbb0eb071d5922b0f8604df3c8493affc173ce401bcb0c46e2b4d1f

(this sample)

  
Delivery method
Distributed via web download

Comments