MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 214f85108169067337c282b59c85bf2b488760ef61bf0e53dd073204dc0cd8fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 214f85108169067337c282b59c85bf2b488760ef61bf0e53dd073204dc0cd8fd |
|---|---|
| SHA3-384 hash: | 5e2694da197a717d306d8f9a7a52efa37ac9b346188c4a08fd5c0ea297c34d29e221e9dbb529b1b9df143ec562f087d4 |
| SHA1 hash: | 44074f8d5cbde0b4faf2f4c1ac987208af625705 |
| MD5 hash: | 8f3be989a258691db33ce2b802a69329 |
| humanhash: | iowa-freddie-seventeen-bluebird |
| File name: | x |
| Download: | download sample |
| File size: | 704 bytes |
| First seen: | 2026-06-18 14:32:28 UTC |
| Last seen: | 2026-06-18 17:08:42 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 12:hKBFKaLcLLDvTWxDrIMTWxDgTWxD6TWpdgWKy:Ar7L8WxPUxtxPfgWKy |
| TLSH | T1540175CF00D618226196CEB8BFA7DC146D86FFD218C24E0CA6C718E3508C9947835F36 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://91.92.42.203/karm7 | d6a860633e869de93f1299d8b3cd7b2ce2e848ee4782093ce4265d5fe8838fc7 | Mirai | botnet mirai |
| http://91.92.42.203/karm5 | 963bab24d0fee05d712e5ca3dfe61865a85858ef0d43cee61785a1c422fb7761 | Mirai | botnet mirai |
| http://91.92.42.203/karm6 | d43ae49d93c621bdc22273954dac78d673b08241ff419057dba269a964ee1938 | Mirai | botnet mirai |
| http://91.92.42.203/karm | 45ee32938be4c01a092ea4d31d8466fa8cd84f1ee856b557cda7cb517c7850de | Mirai | botnet mirai |
Intelligence
File Origin
DEVendor Threat Intelligence
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 214f85108169067337c282b59c85bf2b488760ef61bf0e53dd073204dc0cd8fd
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.