MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3134b84f9b9c74b3ce1a1145fc2cdcf827e2565594e7a8398cf8686ca7700b5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3134b84f9b9c74b3ce1a1145fc2cdcf827e2565594e7a8398cf8686ca7700b5d
SHA3-384 hash: b3e6446e1953fc120b4e06f427c7585de65b7b86183ad59fdbed92680834926b0f36982d6b474a204f5c517803026208
SHA1 hash: 9abda2db2a4942796666c2b927db49b920669d0d
MD5 hash: ac12c4ea89fff7733e90bc41675b3223
humanhash: delta-lactose-ceiling-washington
File name:bins.sh
Download: download sample
File size:121 bytes
First seen:2025-12-23 21:07:47 UTC
Last seen:2025-12-24 13:10:35 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH4vGBwOnQzanFCKlyCAR1iQX7aaIOOdXra+PZn:h9OnFflR0gQLaDyIZn
TLSH T1CDB012C5305980B03C69FDF731A9083231CBD48814C16E281BE83AF2408DE003D50B93
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://209.38.3/ntpdn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=9d0f9901-1800-0000-ffcb-77eb14050000 pid=1300 /usr/bin/sudo guuid=e3528b04-1800-0000-ffcb-77eb1a050000 pid=1306 /tmp/sample.bin guuid=9d0f9901-1800-0000-ffcb-77eb14050000 pid=1300->guuid=e3528b04-1800-0000-ffcb-77eb1a050000 pid=1306 execve guuid=4559f604-1800-0000-ffcb-77eb1c050000 pid=1308 /usr/bin/wget guuid=e3528b04-1800-0000-ffcb-77eb1a050000 pid=1306->guuid=4559f604-1800-0000-ffcb-77eb1c050000 pid=1308 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Text.Browser.Generic
Status:
Suspicious
First seen:
2025-12-23 21:08:24 UTC
File Type:
Text (Shell)
AV detection:
1 of 36 (2.78%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
linux
Behaviour
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3134b84f9b9c74b3ce1a1145fc2cdcf827e2565594e7a8398cf8686ca7700b5d

(this sample)

  
Delivery method
Distributed via web download

Comments