MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2da6979700ca47740c94446df38096017166eecb4206af33aa1d55c9346593ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2da6979700ca47740c94446df38096017166eecb4206af33aa1d55c9346593ea
SHA3-384 hash: cb68f1bed41a9a63247c70b5cf3cd549d9bbd578f61dbcd7855126373e18b9f6ae2fe8a5e4b6aa0c2f63dcdcbf20c96b
SHA1 hash: 42e02081b67eda83a43c8fc70e9516a06a13b9dd
MD5 hash: e95923cac22c8000bf5d3496c793f348
humanhash: king-golf-vegan-alaska
File name:all.sh
Download: download sample
File size:753 bytes
First seen:2026-03-27 11:52:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:YkF1kcClZF70S9fFzHFnfFzHF0fFzHFWGLFfBFS8FBFM5gFNFYGLFfBFSGFBFMDE:ZDkH/FbFFzHFfFzHFgFzHFWGLFZFlFBl
TLSH T15D01928821F2307275FAA8E64A335C2C70C590573DDB2CFCBCA5B0DA95D6C00F042AAD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.81/huhu/titanjr.n/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-26T22:23:00Z UTC
Last seen:
2026-03-28T08:09:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=a905970d-2200-0000-a964-d70d95090000 pid=2453 /usr/bin/sudo guuid=51f40510-2200-0000-a964-d70d96090000 pid=2454 /tmp/sample.bin guuid=a905970d-2200-0000-a964-d70d95090000 pid=2453->guuid=51f40510-2200-0000-a964-d70d96090000 pid=2454 execve guuid=6842db10-2200-0000-a964-d70d97090000 pid=2455 /usr/bin/wget guuid=51f40510-2200-0000-a964-d70d96090000 pid=2454->guuid=6842db10-2200-0000-a964-d70d97090000 pid=2455 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-27 04:59:12 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
linux
Behaviour
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments