MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 220ca3b38128eb2cc5f7d60d203d3fe0c67edce7cec9acad68b131422e91952d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 220ca3b38128eb2cc5f7d60d203d3fe0c67edce7cec9acad68b131422e91952d
SHA3-384 hash: 9849171b8f76cdebf9d02efdb34889a5575aec8cd597138ffc5ac6d4227110c78cc2adf3772c83a463e412c08bb2448a
SHA1 hash: d9e4e16419412a3aada741fd947478df70905f13
MD5 hash: 2483b9cb6dcf940e5fef3c25802cadd2
humanhash: friend-comet-maryland-pasta
File name:nu
Download: download sample
File size:293 bytes
First seen:2025-10-09 04:55:32 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+pUKUF2RVYs5CYf53InkjKM3FoF/fkVKhOXqIKXD73IKX+N1IEWYq1IKBK0:ZtJ+jREY64KF0ghsOTh4WYO80
TLSH T133E02B9DF853487378788CB8B7D72495A50FA20B2E0695CE35CD521EEBE4E60B050593
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-09T02:47:00Z UTC
Last seen:
2025-10-09T03:19:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=f281356e-1800-0000-51b6-b58ac8090000 pid=2504 /usr/bin/sudo guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513 /tmp/sample.bin guuid=f281356e-1800-0000-51b6-b58ac8090000 pid=2504->guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513 execve guuid=04b4dd70-1800-0000-51b6-b58ad3090000 pid=2515 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=04b4dd70-1800-0000-51b6-b58ad3090000 pid=2515 execve guuid=a74da6a4-1800-0000-51b6-b58a660a0000 pid=2662 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=a74da6a4-1800-0000-51b6-b58a660a0000 pid=2662 execve guuid=a6dde9a4-1800-0000-51b6-b58a680a0000 pid=2664 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=a6dde9a4-1800-0000-51b6-b58a680a0000 pid=2664 clone guuid=c03380a5-1800-0000-51b6-b58a6c0a0000 pid=2668 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=c03380a5-1800-0000-51b6-b58a6c0a0000 pid=2668 execve guuid=1ed7d5a5-1800-0000-51b6-b58a6e0a0000 pid=2670 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=1ed7d5a5-1800-0000-51b6-b58a6e0a0000 pid=2670 execve guuid=bc3338d7-1800-0000-51b6-b58ae70a0000 pid=2791 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=bc3338d7-1800-0000-51b6-b58ae70a0000 pid=2791 execve guuid=938172d7-1800-0000-51b6-b58ae90a0000 pid=2793 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=938172d7-1800-0000-51b6-b58ae90a0000 pid=2793 clone guuid=c0a3ecd7-1800-0000-51b6-b58aec0a0000 pid=2796 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=c0a3ecd7-1800-0000-51b6-b58aec0a0000 pid=2796 execve guuid=ff9427d8-1800-0000-51b6-b58aed0a0000 pid=2797 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=ff9427d8-1800-0000-51b6-b58aed0a0000 pid=2797 execve guuid=8c1740f5-1800-0000-51b6-b58a240b0000 pid=2852 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=8c1740f5-1800-0000-51b6-b58a240b0000 pid=2852 execve guuid=0a39c8f5-1800-0000-51b6-b58a270b0000 pid=2855 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=0a39c8f5-1800-0000-51b6-b58a270b0000 pid=2855 clone guuid=429043f7-1800-0000-51b6-b58a2d0b0000 pid=2861 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=429043f7-1800-0000-51b6-b58a2d0b0000 pid=2861 execve guuid=56fc84f7-1800-0000-51b6-b58a2e0b0000 pid=2862 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=56fc84f7-1800-0000-51b6-b58a2e0b0000 pid=2862 execve guuid=d2460616-1900-0000-51b6-b58a7e0b0000 pid=2942 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=d2460616-1900-0000-51b6-b58a7e0b0000 pid=2942 execve guuid=f9624716-1900-0000-51b6-b58a7f0b0000 pid=2943 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=f9624716-1900-0000-51b6-b58a7f0b0000 pid=2943 clone guuid=69e9ee16-1900-0000-51b6-b58a810b0000 pid=2945 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=69e9ee16-1900-0000-51b6-b58a810b0000 pid=2945 execve guuid=5ac33917-1900-0000-51b6-b58a820b0000 pid=2946 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=5ac33917-1900-0000-51b6-b58a820b0000 pid=2946 execve guuid=a4eaf842-1900-0000-51b6-b58af30b0000 pid=3059 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=a4eaf842-1900-0000-51b6-b58af30b0000 pid=3059 execve guuid=bb018443-1900-0000-51b6-b58af60b0000 pid=3062 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=bb018443-1900-0000-51b6-b58af60b0000 pid=3062 clone guuid=44e31645-1900-0000-51b6-b58afa0b0000 pid=3066 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=44e31645-1900-0000-51b6-b58afa0b0000 pid=3066 execve guuid=acc69045-1900-0000-51b6-b58afd0b0000 pid=3069 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=acc69045-1900-0000-51b6-b58afd0b0000 pid=3069 execve guuid=9efe827b-1900-0000-51b6-b58a7c0c0000 pid=3196 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=9efe827b-1900-0000-51b6-b58a7c0c0000 pid=3196 execve guuid=b98ac37b-1900-0000-51b6-b58a7e0c0000 pid=3198 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=b98ac37b-1900-0000-51b6-b58a7e0c0000 pid=3198 clone guuid=b83f457c-1900-0000-51b6-b58a820c0000 pid=3202 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=b83f457c-1900-0000-51b6-b58a820c0000 pid=3202 execve guuid=f4df9d7c-1900-0000-51b6-b58a840c0000 pid=3204 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=f4df9d7c-1900-0000-51b6-b58a840c0000 pid=3204 execve guuid=cc24ae98-1900-0000-51b6-b58aa40c0000 pid=3236 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=cc24ae98-1900-0000-51b6-b58aa40c0000 pid=3236 execve guuid=a2d5e998-1900-0000-51b6-b58aa60c0000 pid=3238 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=a2d5e998-1900-0000-51b6-b58aa60c0000 pid=3238 clone guuid=e528919a-1900-0000-51b6-b58aad0c0000 pid=3245 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=e528919a-1900-0000-51b6-b58aad0c0000 pid=3245 execve guuid=0225f19a-1900-0000-51b6-b58aae0c0000 pid=3246 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=0225f19a-1900-0000-51b6-b58aae0c0000 pid=3246 execve guuid=ee4b2bb1-1900-0000-51b6-b58ac00c0000 pid=3264 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=ee4b2bb1-1900-0000-51b6-b58ac00c0000 pid=3264 execve guuid=df896db1-1900-0000-51b6-b58ac10c0000 pid=3265 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=df896db1-1900-0000-51b6-b58ac10c0000 pid=3265 clone guuid=ab0cb9b2-1900-0000-51b6-b58ac60c0000 pid=3270 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=ab0cb9b2-1900-0000-51b6-b58ac60c0000 pid=3270 execve guuid=e827f6b2-1900-0000-51b6-b58ac80c0000 pid=3272 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=e827f6b2-1900-0000-51b6-b58ac80c0000 pid=3272 execve guuid=763853d0-1900-0000-51b6-b58af00c0000 pid=3312 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=763853d0-1900-0000-51b6-b58af00c0000 pid=3312 execve guuid=002eb6d0-1900-0000-51b6-b58af20c0000 pid=3314 /tmp/dvr.exploit guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=002eb6d0-1900-0000-51b6-b58af20c0000 pid=3314 execve guuid=1589d3d0-1900-0000-51b6-b58af50c0000 pid=3317 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=1589d3d0-1900-0000-51b6-b58af50c0000 pid=3317 execve guuid=a92ccad1-1900-0000-51b6-b58af70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=a92ccad1-1900-0000-51b6-b58af70c0000 pid=3319 execve guuid=8f519ee9-1900-0000-51b6-b58a250d0000 pid=3365 /usr/bin/chmod guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=8f519ee9-1900-0000-51b6-b58a250d0000 pid=3365 execve guuid=a214fce9-1900-0000-51b6-b58a260d0000 pid=3366 /usr/bin/dash guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=a214fce9-1900-0000-51b6-b58a260d0000 pid=3366 clone guuid=771d12ec-1900-0000-51b6-b58a2b0d0000 pid=3371 /usr/bin/rm delete-file guuid=5ed47770-1800-0000-51b6-b58ad1090000 pid=2513->guuid=771d12ec-1900-0000-51b6-b58a2b0d0000 pid=3371 execve 9df19bce-d755-5940-91ff-d0e847757959 109.205.213.5:80 guuid=04b4dd70-1800-0000-51b6-b58ad3090000 pid=2515->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=1ed7d5a5-1800-0000-51b6-b58a6e0a0000 pid=2670->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=ff9427d8-1800-0000-51b6-b58aed0a0000 pid=2797->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=56fc84f7-1800-0000-51b6-b58a2e0b0000 pid=2862->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=5ac33917-1900-0000-51b6-b58a820b0000 pid=2946->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=acc69045-1900-0000-51b6-b58afd0b0000 pid=3069->9df19bce-d755-5940-91ff-d0e847757959 send: 141B guuid=f4df9d7c-1900-0000-51b6-b58a840c0000 pid=3204->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=0225f19a-1900-0000-51b6-b58aae0c0000 pid=3246->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=e827f6b2-1900-0000-51b6-b58ac80c0000 pid=3272->9df19bce-d755-5940-91ff-d0e847757959 send: 140B guuid=d2d8c9d0-1900-0000-51b6-b58af30c0000 pid=3315 /tmp/dvr.exploit zombie guuid=002eb6d0-1900-0000-51b6-b58af20c0000 pid=3314->guuid=d2d8c9d0-1900-0000-51b6-b58af30c0000 pid=3315 clone guuid=4c94d3d0-1900-0000-51b6-b58af60c0000 pid=3318 /tmp/dvr.exploit dns net send-data zombie guuid=d2d8c9d0-1900-0000-51b6-b58af30c0000 pid=3315->guuid=4c94d3d0-1900-0000-51b6-b58af60c0000 pid=3318 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4c94d3d0-1900-0000-51b6-b58af60c0000 pid=3318->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 35B 3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 auth.binaries.lol:41323 guuid=4c94d3d0-1900-0000-51b6-b58af60c0000 pid=3318->3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 send: 11B guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480 /tmp/dvr.exploit net net-scan send-data guuid=4c94d3d0-1900-0000-51b6-b58af60c0000 pid=3318->guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480 clone guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481 /tmp/dvr.exploit net net-scan send-data guuid=4c94d3d0-1900-0000-51b6-b58af60c0000 pid=3318->guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481 clone 5747732c-f603-51c6-9252-e264289619bd auth.binaries.lol:80 guuid=a92ccad1-1900-0000-51b6-b58af70c0000 pid=3319->5747732c-f603-51c6-9252-e264289619bd send: 140B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b8492594-0ba5-5a47-90ff-38a297b48f62 103.43.70.107:23 guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480->b8492594-0ba5-5a47-90ff-38a297b48f62 send: 40B guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480|send-data send-data to 4097 IP addresses review logs to see them all guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480->guuid=f8b85320-1a00-0000-51b6-b58a980d0000 pid=3480|send-data send guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e2dcf4b0-6102-591b-96f6-6cf044fb779f 134.28.37.218:37215 guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481->e2dcf4b0-6102-591b-96f6-6cf044fb779f send: 865B guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481|send-data send-data to 4094 IP addresses review logs to see them all guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481->guuid=dd505a20-1a00-0000-51b6-b58a990d0000 pid=3481|send-data send
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2025-10-09 05:10:05 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Contacts a large (36201) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 220ca3b38128eb2cc5f7d60d203d3fe0c67edce7cec9acad68b131422e91952d

(this sample)

  
Delivery method
Distributed via web download

Comments