🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 29dec28a43a3d5c67a3728bcd26244d5643c100061dc02b024d9435dffa1681a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 29dec28a43a3d5c67a3728bcd26244d5643c100061dc02b024d9435dffa1681a
SHA3-384 hash: 3981a89059d5a91370e477786fdaff2870a9e794c6d2d6cbac39bedaa5143d51d18e048568d37a65a5b1f3dc7f717e94
SHA1 hash: df7dcc2178775e15303fdf2709c05db0b282a058
MD5 hash: cf7889830c967f71d46500dd339915de
humanhash: four-wisconsin-five-south
File name:dl.sh
Download: download sample
File size:6'809 bytes
First seen:2026-09-02 18:16:47 UTC
Last seen:2026-09-02 18:17:50 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:p/SsNXWsdWUiPe1i9L9ivMiBlnn4zigfiynisY:PcQl7
TLSH T146E121D5B9E3683235EE047CABB5B04AA2C7683302197D41F59D77207F281AEF07A719
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
2
# of downloads :
53
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-01T18:41:00Z UTC
Last seen:
2026-09-03T14:53:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d88e49d8-1b00-0000-efbb-776b1c0a0000 pid=2588 /usr/bin/sudo guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601 /tmp/sample.bin guuid=d88e49d8-1b00-0000-efbb-776b1c0a0000 pid=2588->guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601 execve guuid=f0ed2ade-1b00-0000-efbb-776b2b0a0000 pid=2603 /usr/bin/dash guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=f0ed2ade-1b00-0000-efbb-776b2b0a0000 pid=2603 clone guuid=bf4fd9df-1b00-0000-efbb-776b320a0000 pid=2610 /usr/bin/uname guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=bf4fd9df-1b00-0000-efbb-776b320a0000 pid=2610 execve guuid=4c17d8e0-1b00-0000-efbb-776b340a0000 pid=2612 /usr/bin/dash guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=4c17d8e0-1b00-0000-efbb-776b340a0000 pid=2612 clone guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2613 /usr/bin/curl net send-data guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2613 execve guuid=c5b92131-1c00-0000-efbb-776bb70a0000 pid=2743 /usr/bin/wget dns net send-data guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=c5b92131-1c00-0000-efbb-776bb70a0000 pid=2743 execve guuid=79585a75-1c00-0000-efbb-776b0d0b0000 pid=2829 /usr/bin/busybox guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=79585a75-1c00-0000-efbb-776b0d0b0000 pid=2829 execve guuid=8cf9d975-1c00-0000-efbb-776b100b0000 pid=2832 /usr/bin/busybox guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=8cf9d975-1c00-0000-efbb-776b100b0000 pid=2832 execve guuid=a49b1381-1c00-0000-efbb-776b250b0000 pid=2853 /usr/bin/busybox guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=a49b1381-1c00-0000-efbb-776b250b0000 pid=2853 execve guuid=0873b681-1c00-0000-efbb-776b270b0000 pid=2855 /usr/bin/dash guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=0873b681-1c00-0000-efbb-776b270b0000 pid=2855 clone guuid=6779bb81-1c00-0000-efbb-776b280b0000 pid=2856 /usr/bin/busybox dns net send-data write-file guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=6779bb81-1c00-0000-efbb-776b280b0000 pid=2856 execve guuid=caf6a2c1-1c00-0000-efbb-776ba80b0000 pid=2984 /usr/bin/dash guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=caf6a2c1-1c00-0000-efbb-776ba80b0000 pid=2984 clone guuid=aabeeec2-1c00-0000-efbb-776baf0b0000 pid=2991 /usr/bin/python3.11 dns net send-data guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=aabeeec2-1c00-0000-efbb-776baf0b0000 pid=2991 execve guuid=afb1ee31-1d00-0000-efbb-776b2f0c0000 pid=3119 /usr/bin/perl guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=afb1ee31-1d00-0000-efbb-776b2f0c0000 pid=3119 execve guuid=dfd8c832-1d00-0000-efbb-776b310c0000 pid=3121 /usr/bin/busybox guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=dfd8c832-1d00-0000-efbb-776b310c0000 pid=3121 execve guuid=c88c2333-1d00-0000-efbb-776b330c0000 pid=3123 /usr/bin/busybox dns net send-data guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=c88c2333-1d00-0000-efbb-776b330c0000 pid=3123 execve guuid=70408637-2000-0000-efbb-776b9e130000 pid=5022 /usr/bin/curl net guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=70408637-2000-0000-efbb-776b9e130000 pid=5022 execve guuid=09187864-2100-0000-efbb-776b09140000 pid=5129 /usr/bin/busybox guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=09187864-2100-0000-efbb-776b09140000 pid=5129 execve guuid=f0031d65-2100-0000-efbb-776b0a140000 pid=5130 /usr/bin/busybox dns net send-data guuid=dc1764dd-1b00-0000-efbb-776b290a0000 pid=2601->guuid=f0031d65-2100-0000-efbb-776b0a140000 pid=5130 execve guuid=08553ede-1b00-0000-efbb-776b2c0a0000 pid=2604 /usr/bin/dash guuid=f0ed2ade-1b00-0000-efbb-776b2b0a0000 pid=2603->guuid=08553ede-1b00-0000-efbb-776b2c0a0000 pid=2604 clone guuid=831249de-1b00-0000-efbb-776b2d0a0000 pid=2605 /usr/bin/base64 guuid=f0ed2ade-1b00-0000-efbb-776b2b0a0000 pid=2603->guuid=831249de-1b00-0000-efbb-776b2d0a0000 pid=2605 execve guuid=e85853de-1b00-0000-efbb-776b2e0a0000 pid=2606 /usr/bin/tr guuid=f0ed2ade-1b00-0000-efbb-776b2b0a0000 pid=2603->guuid=e85853de-1b00-0000-efbb-776b2e0a0000 pid=2606 execve bbe72a56-95b6-57cb-89a7-11ee50b30138 langec.jewmailer.net:80 guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2613->bbe72a56-95b6-57cb-89a7-11ee50b30138 send: 90B guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2619 /usr/bin/curl dns net send-data guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2613->guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2619 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4ded03e1-1b00-0000-efbb-776b350a0000 pid=2619->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=c5b92131-1c00-0000-efbb-776bb70a0000 pid=2743->bbe72a56-95b6-57cb-89a7-11ee50b30138 send: 141B guuid=c5b92131-1c00-0000-efbb-776bb70a0000 pid=2743->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=6779bb81-1c00-0000-efbb-776b280b0000 pid=2856->bbe72a56-95b6-57cb-89a7-11ee50b30138 send: 52B guuid=6779bb81-1c00-0000-efbb-776b280b0000 pid=2856->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=247ab2c1-1c00-0000-efbb-776ba90b0000 pid=2985 /usr/bin/stat guuid=caf6a2c1-1c00-0000-efbb-776ba80b0000 pid=2984->guuid=247ab2c1-1c00-0000-efbb-776ba90b0000 pid=2985 execve guuid=aabeeec2-1c00-0000-efbb-776baf0b0000 pid=2991->bbe72a56-95b6-57cb-89a7-11ee50b30138 send: 130B guuid=aabeeec2-1c00-0000-efbb-776baf0b0000 pid=2991->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=c88c2333-1d00-0000-efbb-776b330c0000 pid=3123->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B c18c70f8-f32b-55dc-b938-24ce97287e21 langec.jewmailer.net:69 guuid=c88c2333-1d00-0000-efbb-776b330c0000 pid=3123->c18c70f8-f32b-55dc-b938-24ce97287e21 send: 276B a0496d2e-9c3b-509a-adb9-d72dd22fe7fe langec.jewmailer.net:21 guuid=70408637-2000-0000-efbb-776b9e130000 pid=5022->a0496d2e-9c3b-509a-adb9-d72dd22fe7fe con guuid=70408637-2000-0000-efbb-776b9e130000 pid=5029 /usr/bin/curl dns net send-data guuid=70408637-2000-0000-efbb-776b9e130000 pid=5022->guuid=70408637-2000-0000-efbb-776b9e130000 pid=5029 clone guuid=70408637-2000-0000-efbb-776b9e130000 pid=5029->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=f0031d65-2100-0000-efbb-776b0a140000 pid=5130->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-02 18:10:22 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments