🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 478cb2df393c61cb8fd77902d9eab32d7be6a5fca85a5218b6a480bcdc70c123. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 478cb2df393c61cb8fd77902d9eab32d7be6a5fca85a5218b6a480bcdc70c123
SHA3-384 hash: b3a364345a44512158e944a5b53c40e71e881532fed58aca6fdce3187e0d5640a8400b3f2fa4b2789aa6447069181a4a
SHA1 hash: 23cef6bb0c9f6da68bae8c9a55ab39e189bd7e11
MD5 hash: 4b0948d074a98346e4477884a09604e1
humanhash: arkansas-missouri-london-hydrogen
File name:478cb2df393c61cb8fd77902d9eab32d7be6a5fca85a5218b6a480bcdc70c123
Download: download sample
File size:5'787 bytes
First seen:2026-09-14 06:06:19 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:w/b5K9gvuaEbnuEbnv3/majqzY9Vg6IgIMYjTmqAoOJPsNGZsbiT:w/VQXvuYYvmq8uNGZsbO
TLSH T191C132077CA116B1226CC1B95C8761C5F756002B0E587D38B46EBD8C3F18AE1BABC3DA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://nodejs.org/dist/index.jsonn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-18T00:33:00Z UTC
Last seen:
2026-05-18T00:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a0699833-1a00-0000-1dc0-112d100d0000 pid=3344 /usr/bin/sudo guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363 /tmp/sample.bin guuid=a0699833-1a00-0000-1dc0-112d100d0000 pid=3344->guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363 execve guuid=b0045c3a-1a00-0000-1dc0-112d250d0000 pid=3365 /usr/bin/uname guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=b0045c3a-1a00-0000-1dc0-112d250d0000 pid=3365 execve guuid=6421803b-1a00-0000-1dc0-112d2b0d0000 pid=3371 /usr/bin/bash guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=6421803b-1a00-0000-1dc0-112d2b0d0000 pid=3371 clone guuid=b883df5b-1a00-0000-1dc0-112d530d0000 pid=3411 /usr/bin/bash guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=b883df5b-1a00-0000-1dc0-112d530d0000 pid=3411 clone guuid=ed2c085c-1a00-0000-1dc0-112d550d0000 pid=3413 /usr/bin/mkdir guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=ed2c085c-1a00-0000-1dc0-112d550d0000 pid=3413 execve guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3415 /usr/bin/curl net send-data write-file guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3415 execve guuid=56195145-1b00-0000-1dc0-112da50e0000 pid=3749 /usr/bin/tar delete-file write-file guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=56195145-1b00-0000-1dc0-112da50e0000 pid=3749 execve guuid=d2d907a0-2000-0000-1dc0-112d07140000 pid=5127 /usr/bin/rm delete-file guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=d2d907a0-2000-0000-1dc0-112d07140000 pid=5127 execve guuid=1519eba0-2000-0000-1dc0-112d08140000 pid=5128 /root/.vscode/node-v26.8.2-linux-x64/bin/node guuid=fbc6ed39-1a00-0000-1dc0-112d230d0000 pid=3363->guuid=1519eba0-2000-0000-1dc0-112d08140000 pid=5128 execve guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3372 /usr/bin/curl net send-data guuid=6421803b-1a00-0000-1dc0-112d2b0d0000 pid=3371->guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3372 execve guuid=4d1fbd3b-1a00-0000-1dc0-112d2d0d0000 pid=3373 /usr/bin/grep guuid=6421803b-1a00-0000-1dc0-112d2b0d0000 pid=3371->guuid=4d1fbd3b-1a00-0000-1dc0-112d2d0d0000 pid=3373 execve guuid=258ed53b-1a00-0000-1dc0-112d2e0d0000 pid=3374 /usr/bin/head guuid=6421803b-1a00-0000-1dc0-112d2b0d0000 pid=3371->guuid=258ed53b-1a00-0000-1dc0-112d2e0d0000 pid=3374 execve guuid=36b3e43b-1a00-0000-1dc0-112d2f0d0000 pid=3375 /usr/bin/cut guuid=6421803b-1a00-0000-1dc0-112d2b0d0000 pid=3371->guuid=36b3e43b-1a00-0000-1dc0-112d2f0d0000 pid=3375 execve 81b97d64-96dc-5e75-a02c-ce4c884ef31c nodejs.org:443 guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3372->81b97d64-96dc-5e75-a02c-ce4c884ef31c send: 786B guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3379 /usr/bin/curl dns net send-data guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3372->guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3379 clone guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3379->81b97d64-96dc-5e75-a02c-ce4c884ef31c con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4b87ac3b-1a00-0000-1dc0-112d2c0d0000 pid=3379->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3415->81b97d64-96dc-5e75-a02c-ce4c884ef31c send: 902B guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3417 /usr/bin/curl dns net send-data guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3415->guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3417 clone guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3417->81b97d64-96dc-5e75-a02c-ce4c884ef31c con guuid=b6fb615c-1a00-0000-1dc0-112d570d0000 pid=3417->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B guuid=6953d345-1b00-0000-1dc0-112da70e0000 pid=3751 /usr/bin/xz guuid=56195145-1b00-0000-1dc0-112da50e0000 pid=3749->guuid=6953d345-1b00-0000-1dc0-112da70e0000 pid=3751 execve
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-05-18 05:25:17 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm discovery linux
Behaviour
Embeds OpenSSL
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments