MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d346ff21036b3759dae6270ad98d895da68b1b083c533727d66c4be3c6121f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2d346ff21036b3759dae6270ad98d895da68b1b083c533727d66c4be3c6121f6
SHA3-384 hash: a9613937ae97bea19800c34b81d88b5c734cb2f0e36d90df64f3cf6c55c896ab458012074724c87b483559b41804685e
SHA1 hash: be0ac992a8c60b01ce14f6ef3d0f8235c95896fe
MD5 hash: 57fc7c5fc000cebeee565e7d1c095bf7
humanhash: indigo-happy-purple-venus
File name:run.sh
Download: download sample
File size:2'310 bytes
First seen:2025-09-29 04:53:17 UTC
Last seen:2025-09-29 22:00:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:SodKouZnwKhxK9TK9xKR6KRieKihM3zUKJPKdNKtGKdJK/:SodKouZnwKhxK9TK9xKR6KRxK1UKJPKV
TLSH T1E341E98205459B7AA6C2404EF3E4327C6A0FF0821FEBCA0EFDE0856D5EC5D4CA6C5C84
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-29T00:51:00Z UTC
Last seen:
2025-09-29T00:51:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=17c88c01-1800-0000-d782-c2ce390c0000 pid=3129 /usr/bin/sudo guuid=48299e03-1800-0000-d782-c2ce3e0c0000 pid=3134 /tmp/sample.bin guuid=17c88c01-1800-0000-d782-c2ce390c0000 pid=3129->guuid=48299e03-1800-0000-d782-c2ce3e0c0000 pid=3134 execve guuid=61c27904-1800-0000-d782-c2ce400c0000 pid=3136 /usr/bin/wget guuid=48299e03-1800-0000-d782-c2ce3e0c0000 pid=3134->guuid=61c27904-1800-0000-d782-c2ce400c0000 pid=3136 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Downloader.ShellAgnt
Status:
Malicious
First seen:
2025-09-29 04:54:17 UTC
File Type:
Text (Shell)
AV detection:
10 of 38 (26.32%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2d346ff21036b3759dae6270ad98d895da68b1b083c533727d66c4be3c6121f6

(this sample)

  
Delivery method
Distributed via web download

Comments