🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bcc91fdedb8c583a9fe883be9ad453333a1bba0fdf655474982db3cbb8e7a74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2bcc91fdedb8c583a9fe883be9ad453333a1bba0fdf655474982db3cbb8e7a74
SHA3-384 hash: a27ff50cd6e5ed4697cd960425146af46ba3d9840810101832aee07b3792e190fd503c69b882d564bf11917a438deb1e
SHA1 hash: 547969313df72b1aed5ae83523115c618635c080
MD5 hash: 1fff24c4c0b2fa465eb3a9b63e689abd
humanhash: neptune-summer-mockingbird-blossom
File name:2bcc91fdedb8c583a9fe883be9ad453333a1bba0fdf655474982db3cbb8e7a74
Download: download sample
File size:241 bytes
First seen:2026-09-16 20:07:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:9FFMuWf9GenaUfFFYGenNcDfahFFMuWLTLOwfQoNcDy:9FFMuWLntFFUnNphFFMuWLTqwooNZ
TLSH T1AFD05B66142164353B5D4B54535A01E4455E7513CD6859D06492C5E14B1F6444375213
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter beserko
Tags:diicot elf Mexals miner sh XMRIG

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Adware
File Type:
unix shell
First seen:
2026-01-05T08:27:00Z UTC
Last seen:
2026-01-05T08:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0ccccb24-1d00-0000-8b2c-cae17f080000 pid=2175 /usr/bin/sudo guuid=fa70e42a-1d00-0000-8b2c-cae185080000 pid=2181 /tmp/sample.bin guuid=0ccccb24-1d00-0000-8b2c-cae17f080000 pid=2175->guuid=fa70e42a-1d00-0000-8b2c-cae185080000 pid=2181 execve guuid=6850102c-1d00-0000-8b2c-cae186080000 pid=2182 /usr/bin/curl net guuid=fa70e42a-1d00-0000-8b2c-cae185080000 pid=2181->guuid=6850102c-1d00-0000-8b2c-cae186080000 pid=2182 execve guuid=0cfae8be-2000-0000-8b2c-cae1cd0b0000 pid=3021 /usr/bin/curl guuid=fa70e42a-1d00-0000-8b2c-cae185080000 pid=2181->guuid=0cfae8be-2000-0000-8b2c-cae1cd0b0000 pid=3021 execve guuid=ad18f3be-2000-0000-8b2c-cae1ce0b0000 pid=3022 /usr/bin/bash guuid=fa70e42a-1d00-0000-8b2c-cae185080000 pid=2181->guuid=ad18f3be-2000-0000-8b2c-cae1ce0b0000 pid=3022 execve 063e4b67-01cd-5479-88fd-61b47c6d6d27 195.24.237.240:80 guuid=6850102c-1d00-0000-8b2c-cae186080000 pid=2182->063e4b67-01cd-5479-88fd-61b47c6d6d27 con guuid=0cfae8be-2000-0000-8b2c-cae1cd0b0000 pid=3029 /usr/bin/curl dns net send-data guuid=0cfae8be-2000-0000-8b2c-cae1cd0b0000 pid=3021->guuid=0cfae8be-2000-0000-8b2c-cae1cd0b0000 pid=3029 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=0cfae8be-2000-0000-8b2c-cae1cd0b0000 pid=3029->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 294B
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments