🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b3cc9f323462764eea83d26dbdd386b90a4e795d036b5c39b5cc0fe946c06c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3b3cc9f323462764eea83d26dbdd386b90a4e795d036b5c39b5cc0fe946c06c4
SHA3-384 hash: 54181fea41ae711cce7f0e5a491cb84607ca96d5ddf55ea2147bcd8805082ebb92ceffaf2d08e28f231eb7566588f903
SHA1 hash: c0b6494ba4416624323b402ec16bda4bd7a465cd
MD5 hash: 84285f86f93f631d9076bf7a9a47cf6b
humanhash: bulldog-arizona-summer-seventeen
File name:3b3cc9f323462764eea83d26dbdd386b90a4e795d036b5c39b5cc0fe946c06c4
Download: download sample
File size:22'182 bytes
First seen:2026-09-03 07:21:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:tvWX4UIgohUTmAchMPqNLRyFqa15mv1gc9uOz7OqUzf9r8aiFmFYEd9nSQtzaMNB:sX4ooKTS88NWc9uXVr8aiIVlfRPX8yFJ
TLSH T174A2851363DA4AF2245906794D8B1106631952CF06447C287BFEB3186FA5F2E93F2B77
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter hett
Tags:bash dropper honeypot komari script sh shardlure


Avatar
hett
Captured by ShardLure honeypot. Suspected family: Komari. File kind: Shell script. Captured: 2026-08-31.

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Adware
File Type:
unix shell
First seen:
2026-07-23T07:30:00Z UTC
Last seen:
2026-09-04T18:59:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d055104a-1700-0000-87ff-0694580c0000 pid=3160 /usr/bin/sudo guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166 /tmp/sample.bin guuid=d055104a-1700-0000-87ff-0694580c0000 pid=3160->guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166 execve guuid=8aecf74d-1700-0000-87ff-0694610c0000 pid=3169 /usr/bin/uname guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=8aecf74d-1700-0000-87ff-0694610c0000 pid=3169 execve guuid=d6ccd94e-1700-0000-87ff-0694650c0000 pid=3173 /usr/bin/systemctl guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=d6ccd94e-1700-0000-87ff-0694650c0000 pid=3173 execve guuid=4346054f-1700-0000-87ff-0694660c0000 pid=3174 /usr/bin/grep guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=4346054f-1700-0000-87ff-0694660c0000 pid=3174 execve guuid=827fbcca-1700-0000-87ff-0694910d0000 pid=3473 /usr/bin/uname guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=827fbcca-1700-0000-87ff-0694910d0000 pid=3473 execve guuid=505c10cb-1700-0000-87ff-0694940d0000 pid=3476 /usr/bin/mkdir guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=505c10cb-1700-0000-87ff-0694940d0000 pid=3476 execve guuid=7a596dcb-1700-0000-87ff-0694960d0000 pid=3478 /usr/bin/chown guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=7a596dcb-1700-0000-87ff-0694960d0000 pid=3478 execve guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3481 /usr/bin/curl net send-data write-file guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3481 execve guuid=0793322d-1800-0000-87ff-06948c0e0000 pid=3724 /usr/bin/chmod guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=0793322d-1800-0000-87ff-06948c0e0000 pid=3724 execve guuid=24ab9e2d-1800-0000-87ff-06948e0e0000 pid=3726 /usr/bin/chown guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=24ab9e2d-1800-0000-87ff-06948e0e0000 pid=3726 execve guuid=c070182e-1800-0000-87ff-0694920e0000 pid=3730 /usr/bin/bash guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=c070182e-1800-0000-87ff-0694920e0000 pid=3730 clone guuid=965bdf32-1800-0000-87ff-0694a90e0000 pid=3753 /usr/bin/cat write-config guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=965bdf32-1800-0000-87ff-0694a90e0000 pid=3753 execve guuid=99ba5333-1800-0000-87ff-0694ac0e0000 pid=3756 /usr/bin/systemctl guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=99ba5333-1800-0000-87ff-0694ac0e0000 pid=3756 execve guuid=3be10d72-1800-0000-87ff-06946c0f0000 pid=3948 /usr/bin/systemctl guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=3be10d72-1800-0000-87ff-06946c0f0000 pid=3948 execve guuid=1de0c898-1800-0000-87ff-0694ed0f0000 pid=4077 /usr/bin/systemctl guuid=df17064d-1700-0000-87ff-06945e0c0000 pid=3166->guuid=1de0c898-1800-0000-87ff-0694ed0f0000 pid=4077 execve 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3481->75aab096-419b-50ef-be46-7d76b6a90e4c send: 918B f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3481->f0eebea5-e97d-507c-a771-59cac353877c send: 1437B guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3498 /usr/bin/curl dns net send-data guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3481->guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3498 clone guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3557 /usr/bin/curl dns net send-data guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3481->guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3557 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3498->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3557->f0eebea5-e97d-507c-a771-59cac353877c con guuid=538ceecb-1700-0000-87ff-0694990d0000 pid=3557->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 108B guuid=bbb32a2e-1800-0000-87ff-0694930e0000 pid=3731 /usr/bin/bash guuid=c070182e-1800-0000-87ff-0694920e0000 pid=3730->guuid=bbb32a2e-1800-0000-87ff-0694930e0000 pid=3731 clone guuid=36f8d330-1800-0000-87ff-06949f0e0000 pid=3743 /usr/bin/systemctl guuid=c070182e-1800-0000-87ff-0694920e0000 pid=3730->guuid=36f8d330-1800-0000-87ff-06949f0e0000 pid=3743 execve guuid=19763a2e-1800-0000-87ff-0694940e0000 pid=3732 /usr/bin/ps guuid=bbb32a2e-1800-0000-87ff-0694930e0000 pid=3731->guuid=19763a2e-1800-0000-87ff-0694940e0000 pid=3732 execve guuid=dacf412e-1800-0000-87ff-0694950e0000 pid=3733 /usr/bin/tr guuid=bbb32a2e-1800-0000-87ff-0694930e0000 pid=3731->guuid=dacf412e-1800-0000-87ff-0694950e0000 pid=3733 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-03 07:21:21 UTC
File Type:
Text (Shell)
AV detection:
4 of 23 (17.39%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Enumerates running processes
Modifies systemd
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments