MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 463713a9d829a3d60d41e6c80df84b2ac33c79ea09447c3e8e62fd152e4d1c51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 463713a9d829a3d60d41e6c80df84b2ac33c79ea09447c3e8e62fd152e4d1c51
SHA3-384 hash: 5670ea15bf0e24493c43bc71a7b8353b3c54de8d5e945d295a183fe6b9d9fc6d33ed3e5c525e01cafbfbb6279ebe3408
SHA1 hash: e7cd7511e12dd38fa2139ec71b87285fdb3dd3a9
MD5 hash: b3b8e860517c0fc01ce8a55bc09b85c8
humanhash: freddie-winner-india-colorado
File name:link
Download: download sample
File size:294 bytes
First seen:2025-10-19 20:48:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+pUKUF2RVYx8iHYf53I3k2M3FoF/fkVKhOXqIKXD73IKX+N1IEWYq1IKBKW:ZtJ+jRE8KYiHTF0ghsOTh4WYO8W
TLSH T1CEE0C299F852083278748CB9B7DB2451950F920E6E0A558E7189520BEAE4A50B090453
Magika shell
Reporter juroots
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-18T17:00:00Z UTC
Last seen:
2025-10-21T18:33:00Z UTC
Hits:
~100
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=484ef4c0-1900-0000-8122-ac36ad090000 pid=2477 /usr/bin/sudo guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479 /tmp/sample.bin guuid=484ef4c0-1900-0000-8122-ac36ad090000 pid=2477->guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479 execve guuid=af34fbc3-1900-0000-8122-ac36b1090000 pid=2481 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=af34fbc3-1900-0000-8122-ac36b1090000 pid=2481 execve guuid=cae2a8d4-1900-0000-8122-ac36d4090000 pid=2516 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=cae2a8d4-1900-0000-8122-ac36d4090000 pid=2516 execve guuid=026014d5-1900-0000-8122-ac36d6090000 pid=2518 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=026014d5-1900-0000-8122-ac36d6090000 pid=2518 clone guuid=0a99c9d7-1900-0000-8122-ac36de090000 pid=2526 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=0a99c9d7-1900-0000-8122-ac36de090000 pid=2526 execve guuid=08353dd8-1900-0000-8122-ac36e1090000 pid=2529 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=08353dd8-1900-0000-8122-ac36e1090000 pid=2529 execve guuid=fa1521e7-1900-0000-8122-ac36ff090000 pid=2559 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=fa1521e7-1900-0000-8122-ac36ff090000 pid=2559 execve guuid=3364eae7-1900-0000-8122-ac36030a0000 pid=2563 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=3364eae7-1900-0000-8122-ac36030a0000 pid=2563 clone guuid=a43891e8-1900-0000-8122-ac36070a0000 pid=2567 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=a43891e8-1900-0000-8122-ac36070a0000 pid=2567 execve guuid=0099ede8-1900-0000-8122-ac36090a0000 pid=2569 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=0099ede8-1900-0000-8122-ac36090a0000 pid=2569 execve guuid=98a602f5-1900-0000-8122-ac36290a0000 pid=2601 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=98a602f5-1900-0000-8122-ac36290a0000 pid=2601 execve guuid=2fe443f5-1900-0000-8122-ac362a0a0000 pid=2602 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=2fe443f5-1900-0000-8122-ac362a0a0000 pid=2602 clone guuid=85decaf5-1900-0000-8122-ac362d0a0000 pid=2605 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=85decaf5-1900-0000-8122-ac362d0a0000 pid=2605 execve guuid=873b23f6-1900-0000-8122-ac362e0a0000 pid=2606 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=873b23f6-1900-0000-8122-ac362e0a0000 pid=2606 execve guuid=6b41aa01-1a00-0000-8122-ac364e0a0000 pid=2638 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=6b41aa01-1a00-0000-8122-ac364e0a0000 pid=2638 execve guuid=b16ee901-1a00-0000-8122-ac36500a0000 pid=2640 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=b16ee901-1a00-0000-8122-ac36500a0000 pid=2640 clone guuid=11b4ab02-1a00-0000-8122-ac36540a0000 pid=2644 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=11b4ab02-1a00-0000-8122-ac36540a0000 pid=2644 execve guuid=e4a3e402-1a00-0000-8122-ac36560a0000 pid=2646 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=e4a3e402-1a00-0000-8122-ac36560a0000 pid=2646 execve guuid=0d96130f-1a00-0000-8122-ac36760a0000 pid=2678 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=0d96130f-1a00-0000-8122-ac36760a0000 pid=2678 execve guuid=1698860f-1a00-0000-8122-ac36780a0000 pid=2680 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=1698860f-1a00-0000-8122-ac36780a0000 pid=2680 clone guuid=33457010-1a00-0000-8122-ac367d0a0000 pid=2685 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=33457010-1a00-0000-8122-ac367d0a0000 pid=2685 execve guuid=9cc9bf10-1a00-0000-8122-ac367f0a0000 pid=2687 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=9cc9bf10-1a00-0000-8122-ac367f0a0000 pid=2687 execve guuid=68d2e61e-1a00-0000-8122-ac36a80a0000 pid=2728 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=68d2e61e-1a00-0000-8122-ac36a80a0000 pid=2728 execve guuid=2cc0231f-1a00-0000-8122-ac36aa0a0000 pid=2730 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=2cc0231f-1a00-0000-8122-ac36aa0a0000 pid=2730 clone guuid=04eea620-1a00-0000-8122-ac36af0a0000 pid=2735 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=04eea620-1a00-0000-8122-ac36af0a0000 pid=2735 execve guuid=1ac8fe20-1a00-0000-8122-ac36b20a0000 pid=2738 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=1ac8fe20-1a00-0000-8122-ac36b20a0000 pid=2738 execve guuid=39a80f2d-1a00-0000-8122-ac36d30a0000 pid=2771 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=39a80f2d-1a00-0000-8122-ac36d30a0000 pid=2771 execve guuid=c458672d-1a00-0000-8122-ac36d40a0000 pid=2772 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=c458672d-1a00-0000-8122-ac36d40a0000 pid=2772 clone guuid=8386012f-1a00-0000-8122-ac36da0a0000 pid=2778 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=8386012f-1a00-0000-8122-ac36da0a0000 pid=2778 execve guuid=19a2642f-1a00-0000-8122-ac36db0a0000 pid=2779 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=19a2642f-1a00-0000-8122-ac36db0a0000 pid=2779 execve guuid=e5251b3b-1a00-0000-8122-ac36ed0a0000 pid=2797 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=e5251b3b-1a00-0000-8122-ac36ed0a0000 pid=2797 execve guuid=a5cae43b-1a00-0000-8122-ac36ef0a0000 pid=2799 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=a5cae43b-1a00-0000-8122-ac36ef0a0000 pid=2799 clone guuid=8c338c3d-1a00-0000-8122-ac36f30a0000 pid=2803 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=8c338c3d-1a00-0000-8122-ac36f30a0000 pid=2803 execve guuid=3ab1233e-1a00-0000-8122-ac36f50a0000 pid=2805 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=3ab1233e-1a00-0000-8122-ac36f50a0000 pid=2805 execve guuid=5f027b4c-1a00-0000-8122-ac360f0b0000 pid=2831 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=5f027b4c-1a00-0000-8122-ac360f0b0000 pid=2831 execve guuid=86cac64c-1a00-0000-8122-ac36110b0000 pid=2833 /tmp/dlink.exploit guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=86cac64c-1a00-0000-8122-ac36110b0000 pid=2833 execve guuid=6d0cd94c-1a00-0000-8122-ac36130b0000 pid=2835 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=6d0cd94c-1a00-0000-8122-ac36130b0000 pid=2835 execve guuid=8111234d-1a00-0000-8122-ac36160b0000 pid=2838 /usr/bin/wget net send-data write-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=8111234d-1a00-0000-8122-ac36160b0000 pid=2838 execve guuid=8a899b58-1a00-0000-8122-ac36250b0000 pid=2853 /usr/bin/chmod guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=8a899b58-1a00-0000-8122-ac36250b0000 pid=2853 execve guuid=049aff58-1a00-0000-8122-ac36260b0000 pid=2854 /usr/bin/dash guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=049aff58-1a00-0000-8122-ac36260b0000 pid=2854 clone guuid=3330cb59-1a00-0000-8122-ac362b0b0000 pid=2859 /usr/bin/rm delete-file guuid=8da37ec3-1900-0000-8122-ac36af090000 pid=2479->guuid=3330cb59-1a00-0000-8122-ac362b0b0000 pid=2859 execve ce2040a6-1382-57a9-8f72-87c510446939 91.92.241.8:80 guuid=af34fbc3-1900-0000-8122-ac36b1090000 pid=2481->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=08353dd8-1900-0000-8122-ac36e1090000 pid=2529->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=0099ede8-1900-0000-8122-ac36090a0000 pid=2569->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=873b23f6-1900-0000-8122-ac362e0a0000 pid=2606->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=e4a3e402-1a00-0000-8122-ac36560a0000 pid=2646->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=9cc9bf10-1a00-0000-8122-ac367f0a0000 pid=2687->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=1ac8fe20-1a00-0000-8122-ac36b20a0000 pid=2738->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=19a2642f-1a00-0000-8122-ac36db0a0000 pid=2779->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=3ab1233e-1a00-0000-8122-ac36f50a0000 pid=2805->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=84cdd14c-1a00-0000-8122-ac36120b0000 pid=2834 /tmp/dlink.exploit zombie guuid=86cac64c-1a00-0000-8122-ac36110b0000 pid=2833->guuid=84cdd14c-1a00-0000-8122-ac36120b0000 pid=2834 clone guuid=9ba5db4c-1a00-0000-8122-ac36140b0000 pid=2836 /tmp/dlink.exploit dns net send-data zombie guuid=84cdd14c-1a00-0000-8122-ac36120b0000 pid=2834->guuid=9ba5db4c-1a00-0000-8122-ac36140b0000 pid=2836 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=9ba5db4c-1a00-0000-8122-ac36140b0000 pid=2836->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 35B 3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 auth.binaries.lol:41323 guuid=9ba5db4c-1a00-0000-8122-ac36140b0000 pid=2836->3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 send: 11B guuid=3c5a6499-1a00-0000-8122-ac36b70b0000 pid=2999 /tmp/dlink.exploit net net-scan send-data guuid=9ba5db4c-1a00-0000-8122-ac36140b0000 pid=2836->guuid=3c5a6499-1a00-0000-8122-ac36b70b0000 pid=2999 clone guuid=d7876c99-1a00-0000-8122-ac36b80b0000 pid=3000 /tmp/dlink.exploit net net-scan send-data guuid=9ba5db4c-1a00-0000-8122-ac36140b0000 pid=2836->guuid=d7876c99-1a00-0000-8122-ac36b80b0000 pid=3000 clone 5747732c-f603-51c6-9252-e264289619bd auth.binaries.lol:80 guuid=8111234d-1a00-0000-8122-ac36160b0000 pid=2838->5747732c-f603-51c6-9252-e264289619bd send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3c5a6499-1a00-0000-8122-ac36b70b0000 pid=2999->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3c5a6499-1a00-0000-8122-ac36b70b0000 pid=2999|send-data send-data to 4097 IP addresses review logs to see them all guuid=3c5a6499-1a00-0000-8122-ac36b70b0000 pid=2999->guuid=3c5a6499-1a00-0000-8122-ac36b70b0000 pid=2999|send-data send guuid=d7876c99-1a00-0000-8122-ac36b80b0000 pid=3000->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d7876c99-1a00-0000-8122-ac36b80b0000 pid=3000|send-data send-data to 4096 IP addresses review logs to see them all guuid=d7876c99-1a00-0000-8122-ac36b80b0000 pid=3000->guuid=d7876c99-1a00-0000-8122-ac36b80b0000 pid=3000|send-data send
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-10-19 21:10:23 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 463713a9d829a3d60d41e6c80df84b2ac33c79ea09447c3e8e62fd152e4d1c51

(this sample)

  
Delivery method
Distributed via web download

Comments