🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 425bd3bd35f292f5ab20567ba2373f0322352ae2c06114d03c80d293fe76bb68. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 425bd3bd35f292f5ab20567ba2373f0322352ae2c06114d03c80d293fe76bb68
SHA3-384 hash: f4b7ec2e474a965b11daa3c8f7be77c5998ed871d643a9d854d85d18a6dcd1919195c67a8a8bbdc8781f633935cf9194
SHA1 hash: 747bb4003f3616bc3a5e14b087d8f3b8462488bf
MD5 hash: f29a90bef4ff91c62b868bd565a0323b
humanhash: sweet-avocado-robert-oranges
File name:w.sh
Download: download sample
File size:1'048 bytes
First seen:2026-09-17 17:26:19 UTC
Last seen:2026-09-18 14:29:32 UTC
File type: sh
MIME type:text/plain
ssdeep 24:8gxcgycgxcgRK1cg0AM7cgDRdR/2REcgAcgRcgDcggxlcg1:8gxcgycgxcgRScgGcgDjd2OcgAcgRcgc
TLSH T1481151CFA098A003C59ECDC0388BFF06566486F162B52E89AAC856F1B185974B117F08
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139..206/AGbot.armv4ln/an/an/a
http://176.65.139..206/AGbot.armv5ln/an/an/a
http://176.65.139..206/AGbot.armv6ln/an/an/a
http://176.65.139..206/AGbot.armv7ln/an/an/a
http://176.65.139..206/AGbot.i486n/an/an/a
http://176.65.139..206/AGbot.powerpcn/an/an/a
http://176.65.139..206/AGbot.mipsn/an/an/a
http://176.65.139..206/AGbot.mipseln/an/an/a
http://176.65.139..206/AGbot.i586n/an/an/a
http://176.65.139..206/AGbot.x86_64n/an/an/a
http://176.65.139..206/AGbot.i686n/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
text
First seen:
2026-09-17T16:41:00Z UTC
Last seen:
2026-09-19T01:45:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=393cc0b0-1a00-0000-46cc-fc37da080000 pid=2266 /usr/bin/sudo guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268 /tmp/sample.bin guuid=393cc0b0-1a00-0000-46cc-fc37da080000 pid=2266->guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268 execve guuid=91f439b6-1a00-0000-46cc-fc37de080000 pid=2270 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=91f439b6-1a00-0000-46cc-fc37de080000 pid=2270 execve guuid=fea401b7-1a00-0000-46cc-fc37e0080000 pid=2272 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=fea401b7-1a00-0000-46cc-fc37e0080000 pid=2272 execve guuid=eca98cb7-1a00-0000-46cc-fc37e2080000 pid=2274 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=eca98cb7-1a00-0000-46cc-fc37e2080000 pid=2274 clone guuid=385da8b7-1a00-0000-46cc-fc37e4080000 pid=2276 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=385da8b7-1a00-0000-46cc-fc37e4080000 pid=2276 execve guuid=35a645b8-1a00-0000-46cc-fc37e6080000 pid=2278 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=35a645b8-1a00-0000-46cc-fc37e6080000 pid=2278 execve guuid=be81a3b8-1a00-0000-46cc-fc37e8080000 pid=2280 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=be81a3b8-1a00-0000-46cc-fc37e8080000 pid=2280 clone guuid=0c85c1b8-1a00-0000-46cc-fc37e9080000 pid=2281 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=0c85c1b8-1a00-0000-46cc-fc37e9080000 pid=2281 execve guuid=a0e850b9-1a00-0000-46cc-fc37eb080000 pid=2283 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=a0e850b9-1a00-0000-46cc-fc37eb080000 pid=2283 execve guuid=dd36d1b9-1a00-0000-46cc-fc37ed080000 pid=2285 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=dd36d1b9-1a00-0000-46cc-fc37ed080000 pid=2285 clone guuid=2bb8f1b9-1a00-0000-46cc-fc37ee080000 pid=2286 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=2bb8f1b9-1a00-0000-46cc-fc37ee080000 pid=2286 execve guuid=10ac86ba-1a00-0000-46cc-fc37f1080000 pid=2289 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=10ac86ba-1a00-0000-46cc-fc37f1080000 pid=2289 execve guuid=55fd05bb-1a00-0000-46cc-fc37f2080000 pid=2290 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=55fd05bb-1a00-0000-46cc-fc37f2080000 pid=2290 clone guuid=6e3328bb-1a00-0000-46cc-fc37f3080000 pid=2291 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=6e3328bb-1a00-0000-46cc-fc37f3080000 pid=2291 execve guuid=9210d6bb-1a00-0000-46cc-fc37f4080000 pid=2292 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=9210d6bb-1a00-0000-46cc-fc37f4080000 pid=2292 execve guuid=2a13c8bc-1a00-0000-46cc-fc37f5080000 pid=2293 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=2a13c8bc-1a00-0000-46cc-fc37f5080000 pid=2293 clone guuid=f31ce8bc-1a00-0000-46cc-fc37f6080000 pid=2294 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=f31ce8bc-1a00-0000-46cc-fc37f6080000 pid=2294 execve guuid=f58fc6bd-1a00-0000-46cc-fc37f7080000 pid=2295 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=f58fc6bd-1a00-0000-46cc-fc37f7080000 pid=2295 execve guuid=ca1581be-1a00-0000-46cc-fc37f8080000 pid=2296 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=ca1581be-1a00-0000-46cc-fc37f8080000 pid=2296 clone guuid=789ba8be-1a00-0000-46cc-fc37f9080000 pid=2297 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=789ba8be-1a00-0000-46cc-fc37f9080000 pid=2297 execve guuid=08d865bf-1a00-0000-46cc-fc37fa080000 pid=2298 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=08d865bf-1a00-0000-46cc-fc37fa080000 pid=2298 execve guuid=b13706c0-1a00-0000-46cc-fc37fb080000 pid=2299 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=b13706c0-1a00-0000-46cc-fc37fb080000 pid=2299 clone guuid=d1242fc0-1a00-0000-46cc-fc37fc080000 pid=2300 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=d1242fc0-1a00-0000-46cc-fc37fc080000 pid=2300 execve guuid=7548f1c0-1a00-0000-46cc-fc37fd080000 pid=2301 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=7548f1c0-1a00-0000-46cc-fc37fd080000 pid=2301 execve guuid=33d08fc1-1a00-0000-46cc-fc37ff080000 pid=2303 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=33d08fc1-1a00-0000-46cc-fc37ff080000 pid=2303 clone guuid=ad0ea8c1-1a00-0000-46cc-fc3700090000 pid=2304 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=ad0ea8c1-1a00-0000-46cc-fc3700090000 pid=2304 execve guuid=e2b659c2-1a00-0000-46cc-fc3701090000 pid=2305 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=e2b659c2-1a00-0000-46cc-fc3701090000 pid=2305 execve guuid=6fe60bc3-1a00-0000-46cc-fc3702090000 pid=2306 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=6fe60bc3-1a00-0000-46cc-fc3702090000 pid=2306 clone guuid=fb5b16c3-1a00-0000-46cc-fc3703090000 pid=2307 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=fb5b16c3-1a00-0000-46cc-fc3703090000 pid=2307 execve guuid=8313b3c4-1a00-0000-46cc-fc3706090000 pid=2310 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=8313b3c4-1a00-0000-46cc-fc3706090000 pid=2310 execve guuid=753035c5-1a00-0000-46cc-fc3708090000 pid=2312 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=753035c5-1a00-0000-46cc-fc3708090000 pid=2312 clone guuid=017852c5-1a00-0000-46cc-fc370a090000 pid=2314 /usr/bin/busybox guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=017852c5-1a00-0000-46cc-fc370a090000 pid=2314 execve guuid=a8c4fbc5-1a00-0000-46cc-fc370c090000 pid=2316 /usr/bin/chmod guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=a8c4fbc5-1a00-0000-46cc-fc370c090000 pid=2316 execve guuid=a4948fc6-1a00-0000-46cc-fc370e090000 pid=2318 /usr/bin/dash guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=a4948fc6-1a00-0000-46cc-fc370e090000 pid=2318 clone guuid=c251b7c6-1a00-0000-46cc-fc3710090000 pid=2320 /usr/bin/rm delete-file guuid=2e9f58b5-1a00-0000-46cc-fc37dc080000 pid=2268->guuid=c251b7c6-1a00-0000-46cc-fc3710090000 pid=2320 execve
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-09-17 17:27:13 UTC
File Type:
Text (Batch)
AV detection:
10 of 23 (43.48%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 425bd3bd35f292f5ab20567ba2373f0322352ae2c06114d03c80d293fe76bb68

(this sample)

  
Delivery method
Distributed via web download

Comments