MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4017b001b2ed00fb4650bff8bb9e5c6cbaf3946eb6caeec2cb305be9f0439bdc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



JackSkid


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4017b001b2ed00fb4650bff8bb9e5c6cbaf3946eb6caeec2cb305be9f0439bdc
SHA3-384 hash: 7baa28bd4f7f1b3d99fb33176c5af0865287883abd4e2c41944a593f5398b3b144609a01fbbeba0ba932365772e848e7
SHA1 hash: 7181be0738bfec571d55ad0c1df43ec3ba1accd2
MD5 hash: 0ac680662a325166765a2d4f192ea6ce
humanhash: fanta-fillet-twenty-rugby
File name:stager.sh
Download: download sample
Signature JackSkid
File size:630 bytes
First seen:2026-07-26 07:30:04 UTC
Last seen:2026-07-26 07:32:13 UTC
File type: sh
MIME type:text/plain
ssdeep 12:th/GvpcgaunpcgaqpcgaOWpcgaOjBcgaQ2jYovmiPMCDkvmZVQvmHvmPjcYpvmP+:tHun4q4OW4OUQ4YYmiPMxmLAmPmFZm2
TLSH T14CF0780553F02B350C8C051C28A7BC5235152DD836F31ED41BB831685DCB889E3E3DAA
Magika batch
Reporter deepfield
Tags:ddos elf.jackskid jackskid rctea sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
65
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=2398d173-1900-0000-f460-2cdb520b0000 pid=2898 /usr/bin/sudo guuid=1db8807c-1900-0000-f460-2cdb670b0000 pid=2919 /tmp/sample.bin guuid=2398d173-1900-0000-f460-2cdb520b0000 pid=2898->guuid=1db8807c-1900-0000-f460-2cdb670b0000 pid=2919 execve guuid=f212ed7c-1900-0000-f460-2cdb690b0000 pid=2921 /usr/bin/mkdir guuid=1db8807c-1900-0000-f460-2cdb670b0000 pid=2919->guuid=f212ed7c-1900-0000-f460-2cdb690b0000 pid=2921 execve guuid=af89d47d-1900-0000-f460-2cdb6b0b0000 pid=2923 /usr/bin/rm guuid=1db8807c-1900-0000-f460-2cdb670b0000 pid=2919->guuid=af89d47d-1900-0000-f460-2cdb6b0b0000 pid=2923 execve guuid=2ffd5d7e-1900-0000-f460-2cdb6d0b0000 pid=2925 /usr/bin/dash guuid=1db8807c-1900-0000-f460-2cdb670b0000 pid=2919->guuid=2ffd5d7e-1900-0000-f460-2cdb6d0b0000 pid=2925 clone guuid=13b47f7e-1900-0000-f460-2cdb6e0b0000 pid=2926 /usr/bin/dash guuid=2ffd5d7e-1900-0000-f460-2cdb6d0b0000 pid=2925->guuid=13b47f7e-1900-0000-f460-2cdb6e0b0000 pid=2926 clone guuid=09cf997e-1900-0000-f460-2cdb6f0b0000 pid=2927 /usr/bin/busybox net write-file guuid=2ffd5d7e-1900-0000-f460-2cdb6d0b0000 pid=2925->guuid=09cf997e-1900-0000-f460-2cdb6f0b0000 pid=2927 execve 92f94ca8-138c-5613-b8db-c06a787569d4 162.249.125.141:20198 guuid=09cf997e-1900-0000-f460-2cdb6f0b0000 pid=2927->92f94ca8-138c-5613-b8db-c06a787569d4 con
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments