MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d355f96bab2d9535a294cf0c1339779643091460447e1102debac8f58571bb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 2d355f96bab2d9535a294cf0c1339779643091460447e1102debac8f58571bb2
SHA3-384 hash: b2d2e03d2404374ca1f873701705f804342f2a3ef1ad97c0691a6863d7cf8ca8511fe1b5c4944ca13d3f02a0c2279e5e
SHA1 hash: e162b935010cc781d0c1bb175c93154a54ecdabe
MD5 hash: d8ec2eeaabc057f82c11e4d2af0aaa7a
humanhash: georgia-stairway-delaware-fifteen
File name:t
Download: download sample
File size:942 bytes
First seen:2026-07-17 23:09:31 UTC
Last seen:2026-07-18 17:41:06 UTC
File type: sh
MIME type:text/plain
ssdeep 24:QvQhBh9M0otxMZyx9WTxuLxuRWTxixCWTx17x1hWTxgyxFWW:QvQhnooZqWIgRWZWhWRWW
TLSH T1FE11E9AE45C408641641EA0EF5838C37B11F9FDD69C32B9EAD8DAE71708D90C3421EE9
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://217.60.195.214/mips91ee376197f689fe49e7ab6927482f6884a6ad37f19ad38b7850620cc11a3a95 Miraielf mips mirai ua-wget
http://217.60.195.214/mpsl1c3dd2df833307040ddea68767faab876b4817e5160f2f5b8f1a76248833f51c Miraielf mips mirai ua-wget
http://217.60.195.214/arm8e2a423ec6fa3af3e68ab10866de5e0fcae9deaf0e980eb1973b0a0736b5ed93 Miraiarm elf mirai ua-wget
http://217.60.195.214/arm5b7648399204fbb9beaa228be5f4c3882f320dc790534843d6a9762ddfc9413aa Miraiarm elf mirai ua-wget
http://217.60.195.214/arm78fec3546d04243274ac807fceaaec3ad8de6ef7f951aada9112e9abd464a6e2e Miraiarm elf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
441
# of downloads :
11
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-07-17T21:07:00Z UTC
Last seen:
2026-07-17T21:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=1d7f8223-1f00-0000-fa54-a8cd550b0000 pid=2901 /usr/bin/sudo guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908 /tmp/sample.bin guuid=1d7f8223-1f00-0000-fa54-a8cd550b0000 pid=2901->guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908 execve guuid=f9c9362d-1f00-0000-fa54-a8cd6e0b0000 pid=2926 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=f9c9362d-1f00-0000-fa54-a8cd6e0b0000 pid=2926 clone guuid=42d4f53e-1f00-0000-fa54-a8cda00b0000 pid=2976 /usr/bin/chmod guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=42d4f53e-1f00-0000-fa54-a8cda00b0000 pid=2976 execve guuid=f0b8293f-1f00-0000-fa54-a8cda20b0000 pid=2978 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=f0b8293f-1f00-0000-fa54-a8cda20b0000 pid=2978 clone guuid=3f85a33f-1f00-0000-fa54-a8cda50b0000 pid=2981 /usr/bin/rm delete-file guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=3f85a33f-1f00-0000-fa54-a8cda50b0000 pid=2981 execve guuid=838be43f-1f00-0000-fa54-a8cda60b0000 pid=2982 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=838be43f-1f00-0000-fa54-a8cda60b0000 pid=2982 clone guuid=0e34434f-1f00-0000-fa54-a8cdcf0b0000 pid=3023 /usr/bin/chmod guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=0e34434f-1f00-0000-fa54-a8cdcf0b0000 pid=3023 execve guuid=fddea84f-1f00-0000-fa54-a8cdd20b0000 pid=3026 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=fddea84f-1f00-0000-fa54-a8cdd20b0000 pid=3026 clone guuid=07477651-1f00-0000-fa54-a8cdd80b0000 pid=3032 /usr/bin/rm delete-file guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=07477651-1f00-0000-fa54-a8cdd80b0000 pid=3032 execve guuid=70d0ee51-1f00-0000-fa54-a8cdda0b0000 pid=3034 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=70d0ee51-1f00-0000-fa54-a8cdda0b0000 pid=3034 clone guuid=0a22ce61-1f00-0000-fa54-a8cd0c0c0000 pid=3084 /usr/bin/chmod guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=0a22ce61-1f00-0000-fa54-a8cd0c0c0000 pid=3084 execve guuid=fd220c62-1f00-0000-fa54-a8cd0d0c0000 pid=3085 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=fd220c62-1f00-0000-fa54-a8cd0d0c0000 pid=3085 clone guuid=c21ed462-1f00-0000-fa54-a8cd0f0c0000 pid=3087 /usr/bin/rm delete-file guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=c21ed462-1f00-0000-fa54-a8cd0f0c0000 pid=3087 execve guuid=405c2963-1f00-0000-fa54-a8cd100c0000 pid=3088 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=405c2963-1f00-0000-fa54-a8cd100c0000 pid=3088 clone guuid=91c2a274-1f00-0000-fa54-a8cd270c0000 pid=3111 /usr/bin/chmod guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=91c2a274-1f00-0000-fa54-a8cd270c0000 pid=3111 execve guuid=5f174175-1f00-0000-fa54-a8cd280c0000 pid=3112 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=5f174175-1f00-0000-fa54-a8cd280c0000 pid=3112 clone guuid=f570e875-1f00-0000-fa54-a8cd2a0c0000 pid=3114 /usr/bin/rm delete-file guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=f570e875-1f00-0000-fa54-a8cd2a0c0000 pid=3114 execve guuid=43bd3976-1f00-0000-fa54-a8cd2b0c0000 pid=3115 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=43bd3976-1f00-0000-fa54-a8cd2b0c0000 pid=3115 clone guuid=ce383485-1f00-0000-fa54-a8cd360c0000 pid=3126 /usr/bin/chmod guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=ce383485-1f00-0000-fa54-a8cd360c0000 pid=3126 execve guuid=c6818a85-1f00-0000-fa54-a8cd380c0000 pid=3128 /usr/bin/dash guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=c6818a85-1f00-0000-fa54-a8cd380c0000 pid=3128 clone guuid=79094086-1f00-0000-fa54-a8cd3a0c0000 pid=3130 /usr/bin/rm delete-file guuid=1f096325-1f00-0000-fa54-a8cd5c0b0000 pid=2908->guuid=79094086-1f00-0000-fa54-a8cd3a0c0000 pid=3130 execve guuid=8641472d-1f00-0000-fa54-a8cd6f0b0000 pid=2927 /usr/bin/wget net send-data write-file guuid=f9c9362d-1f00-0000-fa54-a8cd6e0b0000 pid=2926->guuid=8641472d-1f00-0000-fa54-a8cd6f0b0000 pid=2927 execve f692037b-ed4e-5131-96ee-49a294b0f977 217.60.195.214:80 guuid=8641472d-1f00-0000-fa54-a8cd6f0b0000 pid=2927->f692037b-ed4e-5131-96ee-49a294b0f977 send: 133B guuid=b837f33f-1f00-0000-fa54-a8cda80b0000 pid=2984 /usr/bin/wget net send-data write-file guuid=838be43f-1f00-0000-fa54-a8cda60b0000 pid=2982->guuid=b837f33f-1f00-0000-fa54-a8cda80b0000 pid=2984 execve guuid=b837f33f-1f00-0000-fa54-a8cda80b0000 pid=2984->f692037b-ed4e-5131-96ee-49a294b0f977 send: 133B guuid=2a60fa51-1f00-0000-fa54-a8cddb0b0000 pid=3035 /usr/bin/wget net send-data write-file guuid=70d0ee51-1f00-0000-fa54-a8cdda0b0000 pid=3034->guuid=2a60fa51-1f00-0000-fa54-a8cddb0b0000 pid=3035 execve guuid=2a60fa51-1f00-0000-fa54-a8cddb0b0000 pid=3035->f692037b-ed4e-5131-96ee-49a294b0f977 send: 132B guuid=3e5c3d63-1f00-0000-fa54-a8cd110c0000 pid=3089 /usr/bin/wget net send-data write-file guuid=405c2963-1f00-0000-fa54-a8cd100c0000 pid=3088->guuid=3e5c3d63-1f00-0000-fa54-a8cd110c0000 pid=3089 execve guuid=3e5c3d63-1f00-0000-fa54-a8cd110c0000 pid=3089->f692037b-ed4e-5131-96ee-49a294b0f977 send: 133B guuid=21284876-1f00-0000-fa54-a8cd2c0c0000 pid=3116 /usr/bin/wget net send-data write-file guuid=43bd3976-1f00-0000-fa54-a8cd2b0c0000 pid=3115->guuid=21284876-1f00-0000-fa54-a8cd2c0c0000 pid=3116 execve guuid=21284876-1f00-0000-fa54-a8cd2c0c0000 pid=3116->f692037b-ed4e-5131-96ee-49a294b0f977 send: 133B
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-18 02:37:13 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 2d355f96bab2d9535a294cf0c1339779643091460447e1102debac8f58571bb2

(this sample)

  
Delivery method
Distributed via web download

Comments