MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d9a69c44348dfcd37a539e56e5ed8725ee26816ff7c489940d990b4759c3eb5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3d9a69c44348dfcd37a539e56e5ed8725ee26816ff7c489940d990b4759c3eb5
SHA3-384 hash: 25811fa1ea2e22b46c8fc0f31e39cca35e1250f3cc4c8bfe38c0bbcbe87df183c30e7ff4eba814cb94d854b7347f9306
SHA1 hash: 38048c511a96bd06b4d02888dd0eb283c0b6a560
MD5 hash: a1c7d0979f83c94c4e16a7520221ee44
humanhash: beer-steak-mockingbird-three
File name:t
Download: download sample
File size:647 bytes
First seen:2025-08-28 07:33:20 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:CsBXi6ckSLOIsnsBXi6cvNgROlzGjsBXi6cOnmGjsBXi6cBLGjsBXi6cpe8NI1uX:Pi6X4hi6gN186i6N6i6d6i6iNNI886iQ
TLSH T1F8F075FF08157AB0C8A9F8337252D8EE900B95D222BA4E5A5B8E0573CE69514F03498D
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.121.13.159/nktmipsn/an/aelf ua-wget
http://185.121.13.159/nktmpsln/an/aelf ua-wget
http://185.121.13.159/nktarm4n/an/aelf ua-wget
http://185.121.13.159/nktarm5n/an/aelf ua-wget
http://185.121.13.159/nktarm6n/an/aelf ua-wget
http://185.121.13.159/nktarm7n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-08-28T06:18:00Z UTC
Last seen:
2025-08-28T06:18:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=79c4ce1d-1800-0000-b64e-6f77490d0000 pid=3401 /usr/bin/sudo guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409 /tmp/sample.bin guuid=79c4ce1d-1800-0000-b64e-6f77490d0000 pid=3401->guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409 execve guuid=89abb820-1800-0000-b64e-6f77520d0000 pid=3410 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=89abb820-1800-0000-b64e-6f77520d0000 pid=3410 execve guuid=cd443f21-1800-0000-b64e-6f77550d0000 pid=3413 /usr/bin/wget net send-data guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=cd443f21-1800-0000-b64e-6f77550d0000 pid=3413 execve guuid=219fc624-1800-0000-b64e-6f77620d0000 pid=3426 /usr/bin/chmod guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=219fc624-1800-0000-b64e-6f77620d0000 pid=3426 execve guuid=d7810f25-1800-0000-b64e-6f77640d0000 pid=3428 /usr/bin/dash guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=d7810f25-1800-0000-b64e-6f77640d0000 pid=3428 clone guuid=74211e25-1800-0000-b64e-6f77650d0000 pid=3429 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=74211e25-1800-0000-b64e-6f77650d0000 pid=3429 execve guuid=be7a5d25-1800-0000-b64e-6f77670d0000 pid=3431 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=be7a5d25-1800-0000-b64e-6f77670d0000 pid=3431 execve guuid=94f3a525-1800-0000-b64e-6f776a0d0000 pid=3434 /usr/bin/wget net send-data guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=94f3a525-1800-0000-b64e-6f776a0d0000 pid=3434 execve guuid=21396228-1800-0000-b64e-6f77750d0000 pid=3445 /usr/bin/chmod guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=21396228-1800-0000-b64e-6f77750d0000 pid=3445 execve guuid=da48a728-1800-0000-b64e-6f77770d0000 pid=3447 /usr/bin/dash guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=da48a728-1800-0000-b64e-6f77770d0000 pid=3447 clone guuid=9b5fb728-1800-0000-b64e-6f77780d0000 pid=3448 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=9b5fb728-1800-0000-b64e-6f77780d0000 pid=3448 execve guuid=f7acf928-1800-0000-b64e-6f777a0d0000 pid=3450 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=f7acf928-1800-0000-b64e-6f777a0d0000 pid=3450 execve guuid=b6b44229-1800-0000-b64e-6f777c0d0000 pid=3452 /usr/bin/wget net send-data guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=b6b44229-1800-0000-b64e-6f777c0d0000 pid=3452 execve guuid=5581202d-1800-0000-b64e-6f778a0d0000 pid=3466 /usr/bin/chmod guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=5581202d-1800-0000-b64e-6f778a0d0000 pid=3466 execve guuid=8158772d-1800-0000-b64e-6f778b0d0000 pid=3467 /usr/bin/dash guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=8158772d-1800-0000-b64e-6f778b0d0000 pid=3467 clone guuid=4c6b872d-1800-0000-b64e-6f778c0d0000 pid=3468 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=4c6b872d-1800-0000-b64e-6f778c0d0000 pid=3468 execve guuid=4bb9c72d-1800-0000-b64e-6f778e0d0000 pid=3470 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=4bb9c72d-1800-0000-b64e-6f778e0d0000 pid=3470 execve guuid=8ce00c2e-1800-0000-b64e-6f77900d0000 pid=3472 /usr/bin/wget net send-data guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=8ce00c2e-1800-0000-b64e-6f77900d0000 pid=3472 execve guuid=878f0232-1800-0000-b64e-6f779d0d0000 pid=3485 /usr/bin/chmod guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=878f0232-1800-0000-b64e-6f779d0d0000 pid=3485 execve guuid=dcdb4632-1800-0000-b64e-6f779f0d0000 pid=3487 /usr/bin/dash guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=dcdb4632-1800-0000-b64e-6f779f0d0000 pid=3487 clone guuid=c4bd5132-1800-0000-b64e-6f77a00d0000 pid=3488 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=c4bd5132-1800-0000-b64e-6f77a00d0000 pid=3488 execve guuid=df0a9e32-1800-0000-b64e-6f77a20d0000 pid=3490 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=df0a9e32-1800-0000-b64e-6f77a20d0000 pid=3490 execve guuid=8811e432-1800-0000-b64e-6f77a40d0000 pid=3492 /usr/bin/wget net send-data guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=8811e432-1800-0000-b64e-6f77a40d0000 pid=3492 execve guuid=4308da35-1800-0000-b64e-6f77ab0d0000 pid=3499 /usr/bin/chmod guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=4308da35-1800-0000-b64e-6f77ab0d0000 pid=3499 execve guuid=df643a36-1800-0000-b64e-6f77ac0d0000 pid=3500 /usr/bin/dash guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=df643a36-1800-0000-b64e-6f77ac0d0000 pid=3500 clone guuid=58884836-1800-0000-b64e-6f77ad0d0000 pid=3501 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=58884836-1800-0000-b64e-6f77ad0d0000 pid=3501 execve guuid=44e1b336-1800-0000-b64e-6f77ae0d0000 pid=3502 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=44e1b336-1800-0000-b64e-6f77ae0d0000 pid=3502 execve guuid=090d0337-1800-0000-b64e-6f77af0d0000 pid=3503 /usr/bin/wget net send-data guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=090d0337-1800-0000-b64e-6f77af0d0000 pid=3503 execve guuid=30780b3a-1800-0000-b64e-6f77b40d0000 pid=3508 /usr/bin/chmod guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=30780b3a-1800-0000-b64e-6f77b40d0000 pid=3508 execve guuid=819c523a-1800-0000-b64e-6f77b60d0000 pid=3510 /usr/bin/dash guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=819c523a-1800-0000-b64e-6f77b60d0000 pid=3510 clone guuid=b0d5693a-1800-0000-b64e-6f77b70d0000 pid=3511 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=b0d5693a-1800-0000-b64e-6f77b70d0000 pid=3511 execve guuid=66bed53a-1800-0000-b64e-6f77b80d0000 pid=3512 /usr/bin/rm guuid=3df66f20-1800-0000-b64e-6f77510d0000 pid=3409->guuid=66bed53a-1800-0000-b64e-6f77b80d0000 pid=3512 execve 46c5cf3c-ed7d-558b-b835-3a135f52a779 185.121.13.159:80 guuid=cd443f21-1800-0000-b64e-6f77550d0000 pid=3413->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 136B guuid=94f3a525-1800-0000-b64e-6f776a0d0000 pid=3434->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 136B guuid=b6b44229-1800-0000-b64e-6f777c0d0000 pid=3452->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 136B guuid=8ce00c2e-1800-0000-b64e-6f77900d0000 pid=3472->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 136B guuid=8811e432-1800-0000-b64e-6f77a40d0000 pid=3492->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 136B guuid=090d0337-1800-0000-b64e-6f77af0d0000 pid=3503->46c5cf3c-ed7d-558b-b835-3a135f52a779 send: 136B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-28 06:37:10 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3d9a69c44348dfcd37a539e56e5ed8725ee26816ff7c489940d990b4759c3eb5

(this sample)

  
Delivery method
Distributed via web download

Comments