MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 38d7165e0c560a6b3eded745678a8a2a458ed2ef55b004fa8b8186814aa2d13e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 38d7165e0c560a6b3eded745678a8a2a458ed2ef55b004fa8b8186814aa2d13e
SHA3-384 hash: 1485789d4c3b2019c8096b3abb2722dd6a666985518a08d3de1eaad482185f54c3b21ebda0a9b19bb463d0d3a98c042f
SHA1 hash: 4fba1e93fce97ded5968925d520293995092e905
MD5 hash: fa362e0e53d5d4fc582455cff2219061
humanhash: nineteen-enemy-victor-artist
File name:ll.sh
Download: download sample
File size:591 bytes
First seen:2026-01-21 22:31:36 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3UUYNUU7ALKVNUUP0LKBNUU5eTtgNUUifyNUUAj4NUUcseNUUuOmNUUWzNUUSv:3J3uKKVyt1RNsR0sv
TLSH T1CCF0E1EC65F66543DA29DE04B0E6812C9402D2CA3DF3CE95E83C09307CC71003918B6B
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Verdict:
Malicious
File Type:
ps1
First seen:
2026-01-17T21:47:00Z UTC
Last seen:
2026-01-21T17:05:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=7a3e14cc-1a00-0000-425c-8fe18f0c0000 pid=3215 /usr/bin/sudo guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220 /tmp/sample.bin guuid=7a3e14cc-1a00-0000-425c-8fe18f0c0000 pid=3215->guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220 execve guuid=3106d8ce-1a00-0000-425c-8fe1960c0000 pid=3222 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=3106d8ce-1a00-0000-425c-8fe1960c0000 pid=3222 execve guuid=047970db-1a00-0000-425c-8fe1a10c0000 pid=3233 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=047970db-1a00-0000-425c-8fe1a10c0000 pid=3233 execve guuid=e633dfdb-1a00-0000-425c-8fe1a20c0000 pid=3234 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=e633dfdb-1a00-0000-425c-8fe1a20c0000 pid=3234 clone guuid=e505f5db-1a00-0000-425c-8fe1a30c0000 pid=3235 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=e505f5db-1a00-0000-425c-8fe1a30c0000 pid=3235 execve guuid=cf521eea-1a00-0000-425c-8fe1bc0c0000 pid=3260 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=cf521eea-1a00-0000-425c-8fe1bc0c0000 pid=3260 execve guuid=bfc155ea-1a00-0000-425c-8fe1bd0c0000 pid=3261 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=bfc155ea-1a00-0000-425c-8fe1bd0c0000 pid=3261 clone guuid=b28b5eea-1a00-0000-425c-8fe1be0c0000 pid=3262 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=b28b5eea-1a00-0000-425c-8fe1be0c0000 pid=3262 execve guuid=995410f0-1a00-0000-425c-8fe1d00c0000 pid=3280 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=995410f0-1a00-0000-425c-8fe1d00c0000 pid=3280 execve guuid=42194cf0-1a00-0000-425c-8fe1d20c0000 pid=3282 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=42194cf0-1a00-0000-425c-8fe1d20c0000 pid=3282 clone guuid=fcb456f0-1a00-0000-425c-8fe1d30c0000 pid=3283 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=fcb456f0-1a00-0000-425c-8fe1d30c0000 pid=3283 execve guuid=17ed68f4-1a00-0000-425c-8fe1e10c0000 pid=3297 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=17ed68f4-1a00-0000-425c-8fe1e10c0000 pid=3297 execve guuid=2ea6b0f4-1a00-0000-425c-8fe1e20c0000 pid=3298 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=2ea6b0f4-1a00-0000-425c-8fe1e20c0000 pid=3298 clone guuid=59b0b9f4-1a00-0000-425c-8fe1e30c0000 pid=3299 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=59b0b9f4-1a00-0000-425c-8fe1e30c0000 pid=3299 execve guuid=1a5fcafe-1a00-0000-425c-8fe1f50c0000 pid=3317 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=1a5fcafe-1a00-0000-425c-8fe1f50c0000 pid=3317 execve guuid=7bde2cff-1a00-0000-425c-8fe1f70c0000 pid=3319 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=7bde2cff-1a00-0000-425c-8fe1f70c0000 pid=3319 clone guuid=c12133ff-1a00-0000-425c-8fe1f90c0000 pid=3321 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=c12133ff-1a00-0000-425c-8fe1f90c0000 pid=3321 execve guuid=004e1c04-1b00-0000-425c-8fe1050d0000 pid=3333 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=004e1c04-1b00-0000-425c-8fe1050d0000 pid=3333 execve guuid=dd5e9504-1b00-0000-425c-8fe1070d0000 pid=3335 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=dd5e9504-1b00-0000-425c-8fe1070d0000 pid=3335 clone guuid=5f3caf04-1b00-0000-425c-8fe1090d0000 pid=3337 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=5f3caf04-1b00-0000-425c-8fe1090d0000 pid=3337 execve guuid=1c15a00a-1b00-0000-425c-8fe10e0d0000 pid=3342 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=1c15a00a-1b00-0000-425c-8fe10e0d0000 pid=3342 execve guuid=e936160b-1b00-0000-425c-8fe10f0d0000 pid=3343 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=e936160b-1b00-0000-425c-8fe10f0d0000 pid=3343 clone guuid=db31230b-1b00-0000-425c-8fe1100d0000 pid=3344 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=db31230b-1b00-0000-425c-8fe1100d0000 pid=3344 execve guuid=ecc65116-1b00-0000-425c-8fe1180d0000 pid=3352 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=ecc65116-1b00-0000-425c-8fe1180d0000 pid=3352 execve guuid=42399716-1b00-0000-425c-8fe11a0d0000 pid=3354 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=42399716-1b00-0000-425c-8fe11a0d0000 pid=3354 clone guuid=2b4caf16-1b00-0000-425c-8fe11b0d0000 pid=3355 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=2b4caf16-1b00-0000-425c-8fe11b0d0000 pid=3355 execve guuid=69e7c31f-1b00-0000-425c-8fe12e0d0000 pid=3374 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=69e7c31f-1b00-0000-425c-8fe12e0d0000 pid=3374 execve guuid=0f6a1020-1b00-0000-425c-8fe12f0d0000 pid=3375 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=0f6a1020-1b00-0000-425c-8fe12f0d0000 pid=3375 clone guuid=5df51d20-1b00-0000-425c-8fe1300d0000 pid=3376 /usr/bin/curl net guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=5df51d20-1b00-0000-425c-8fe1300d0000 pid=3376 execve guuid=a8a2882b-1b00-0000-425c-8fe14b0d0000 pid=3403 /usr/bin/chmod guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=a8a2882b-1b00-0000-425c-8fe14b0d0000 pid=3403 execve guuid=2372d02b-1b00-0000-425c-8fe14d0d0000 pid=3405 /usr/bin/dash guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=2372d02b-1b00-0000-425c-8fe14d0d0000 pid=3405 clone guuid=8d5ddb2b-1b00-0000-425c-8fe14e0d0000 pid=3406 /usr/bin/rm delete-file guuid=739d84ce-1a00-0000-425c-8fe1940c0000 pid=3220->guuid=8d5ddb2b-1b00-0000-425c-8fe14e0d0000 pid=3406 execve b8c32f6f-e0ff-5b69-a443-652e84386a76 158.94.208.27:80 guuid=3106d8ce-1a00-0000-425c-8fe1960c0000 pid=3222->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=e505f5db-1a00-0000-425c-8fe1a30c0000 pid=3235->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=b28b5eea-1a00-0000-425c-8fe1be0c0000 pid=3262->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=fcb456f0-1a00-0000-425c-8fe1d30c0000 pid=3283->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=59b0b9f4-1a00-0000-425c-8fe1e30c0000 pid=3299->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=c12133ff-1a00-0000-425c-8fe1f90c0000 pid=3321->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=5f3caf04-1b00-0000-425c-8fe1090d0000 pid=3337->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=db31230b-1b00-0000-425c-8fe1100d0000 pid=3344->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=2b4caf16-1b00-0000-425c-8fe11b0d0000 pid=3355->b8c32f6f-e0ff-5b69-a443-652e84386a76 con guuid=5df51d20-1b00-0000-425c-8fe1300d0000 pid=3376->b8c32f6f-e0ff-5b69-a443-652e84386a76 con
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Worm.Mirai
Status:
Malicious
First seen:
2026-01-18 03:30:49 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 38d7165e0c560a6b3eded745678a8a2a458ed2ef55b004fa8b8186814aa2d13e

(this sample)

  
Delivery method
Distributed via web download

Comments