MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2d346ff21036b3759dae6270ad98d895da68b1b083c533727d66c4be3c6121f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | 2d346ff21036b3759dae6270ad98d895da68b1b083c533727d66c4be3c6121f6 |
|---|---|
| SHA3-384 hash: | a9613937ae97bea19800c34b81d88b5c734cb2f0e36d90df64f3cf6c55c896ab458012074724c87b483559b41804685e |
| SHA1 hash: | be0ac992a8c60b01ce14f6ef3d0f8235c95896fe |
| MD5 hash: | 57fc7c5fc000cebeee565e7d1c095bf7 |
| humanhash: | indigo-happy-purple-venus |
| File name: | run.sh |
| Download: | download sample |
| File size: | 2'310 bytes |
| First seen: | 2025-09-29 04:53:17 UTC |
| Last seen: | 2025-09-29 22:00:41 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 48:SodKouZnwKhxK9TK9xKR6KRieKihM3zUKJPKdNKtGKdJK/:SodKouZnwKhxK9TK9xKR6KRxK1UKJPKV |
| TLSH | T1E341E98205459B7AA6C2404EF3E4327C6A0FF0821FEBCA0EFDE0856D5EC5D4CA6C5C84 |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Intelligence
File Origin
# of uploads :
2
# of downloads :
55
Origin country :
DEVendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-29T00:51:00Z UTC
Last seen:
2025-09-29T00:51:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
Score:
32%
Verdict:
Susipicious
File Type:
SCRIPT
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Downloader.ShellAgnt
Status:
Malicious
First seen:
2025-09-29 04:54:17 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
3/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.39
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 2d346ff21036b3759dae6270ad98d895da68b1b083c533727d66c4be3c6121f6
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.