🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 47c0d92b76fc8399a217da9e169042ee66639bb84da848e6db259736f30320b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 47c0d92b76fc8399a217da9e169042ee66639bb84da848e6db259736f30320b0
SHA3-384 hash: 92b03f3b73c89c5daf9f4d1baa7cf6af8c6b17dcc1155a80956e93f7b931ca509dd952d199390b37d75966e549d9c116
SHA1 hash: dcb28dd8508ec2e93cfe18b95f333c238626c967
MD5 hash: 6c4810e02ca3332a9b8b8ebd1234acff
humanhash: uncle-tennessee-july-enemy
File name:tokenlinux.sh
Download: download sample
File size:3'052 bytes
First seen:2026-09-30 18:11:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:CsJszGzsSpRQFlxj62mgn13mgc6Dxp8sg89QTg9MilViJGf/fzs6s6GxAw+XlVXH:CsJQGz/pRQF/j62mgn13mgcC8789wg1t
TLSH T131512392F45722F32374C5A488EA31D4212B205B4EDD3A14B5FDBF5C3B25591B26EA0B
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter arados
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
HR HR
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-16T06:13:00Z UTC
Last seen:
2026-10-02T05:38:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=c0b81da2-1800-0000-a171-1015ab0c0000 pid=3243 /usr/bin/sudo guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249 /tmp/sample.bin guuid=c0b81da2-1800-0000-a171-1015ab0c0000 pid=3243->guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249 execve guuid=134f66a4-1800-0000-a171-1015b30c0000 pid=3251 /usr/bin/uname guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=134f66a4-1800-0000-a171-1015b30c0000 pid=3251 execve guuid=c669aba4-1800-0000-a171-1015b40c0000 pid=3252 /usr/bin/uname guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=c669aba4-1800-0000-a171-1015b40c0000 pid=3252 execve guuid=27f4eda4-1800-0000-a171-1015b50c0000 pid=3253 /usr/bin/bash guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=27f4eda4-1800-0000-a171-1015b50c0000 pid=3253 clone guuid=587015a5-1800-0000-a171-1015b70c0000 pid=3255 /usr/bin/bash guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=587015a5-1800-0000-a171-1015b70c0000 pid=3255 clone guuid=7cb328a5-1800-0000-a171-1015b90c0000 pid=3257 /usr/bin/mkdir guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=7cb328a5-1800-0000-a171-1015b90c0000 pid=3257 execve guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3260 /usr/bin/curl net send-data write-file guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3260 execve guuid=e35ad757-1900-0000-a171-1015f70d0000 pid=3575 /usr/bin/tar delete-file write-file guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=e35ad757-1900-0000-a171-1015f70d0000 pid=3575 execve guuid=45711d58-1d00-0000-a171-1015fc130000 pid=5116 /usr/bin/rm delete-file guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=45711d58-1d00-0000-a171-1015fc130000 pid=5116 execve guuid=a3715659-1d00-0000-a171-1015fd130000 pid=5117 /usr/bin/mkdir guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=a3715659-1d00-0000-a171-1015fd130000 pid=5117 execve guuid=655b415a-1d00-0000-a171-1015fe130000 pid=5118 /usr/bin/curl net send-data write-file guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=655b415a-1d00-0000-a171-1015fe130000 pid=5118 execve guuid=94aaa05e-1d00-0000-a171-1015ff130000 pid=5119 /usr/bin/curl net send-data write-file guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=94aaa05e-1d00-0000-a171-1015ff130000 pid=5119 execve guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120 /root/.task/node-v20.11.1-linux-x64/bin/node mprotect-exec net send-data write-file guuid=82d917a4-1800-0000-a171-1015b10c0000 pid=3249->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120 execve guuid=7b64f9a4-1800-0000-a171-1015b60c0000 pid=3254 /usr/bin/bash guuid=27f4eda4-1800-0000-a171-1015b50c0000 pid=3253->guuid=7b64f9a4-1800-0000-a171-1015b60c0000 pid=3254 clone 81b97d64-96dc-5e75-a02c-ce4c884ef31c nodejs.org:443 guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3260->81b97d64-96dc-5e75-a02c-ce4c884ef31c send: 855B guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3284 /usr/bin/curl dns net send-data guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3260->guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3284 clone guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3284->81b97d64-96dc-5e75-a02c-ce4c884ef31c con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=94b3e9a6-1800-0000-a171-1015bc0c0000 pid=3284->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B guuid=d8188458-1900-0000-a171-1015f80d0000 pid=3576 /usr/bin/xz guuid=e35ad757-1900-0000-a171-1015f70d0000 pid=3575->guuid=d8188458-1900-0000-a171-1015f80d0000 pid=3576 execve ea66628e-eb9c-5f70-9f18-2795b89c8043 84.200.33.163:80 guuid=655b415a-1d00-0000-a171-1015fe130000 pid=5118->ea66628e-eb9c-5f70-9f18-2795b89c8043 send: 90B guuid=94aaa05e-1d00-0000-a171-1015ff130000 pid=5119->ea66628e-eb9c-5f70-9f18-2795b89c8043 send: 93B ef312cd3-e087-551d-ad09-2636fbdaaf04 registry.npmjs.org:443 guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->ef312cd3-e087-551d-ad09-2636fbdaaf04 send: 229948B guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5121 /root/.task/node-v20.11.1-linux-x64/bin/node guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5121 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5122 /root/.task/node-v20.11.1-linux-x64/bin/node guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5122 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5123 /root/.task/node-v20.11.1-linux-x64/bin/node guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5123 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5124 /root/.task/node-v20.11.1-linux-x64/bin/node guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5124 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5125 /root/.task/node-v20.11.1-linux-x64/bin/node guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5125 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5126 /root/.task/node-v20.11.1-linux-x64/bin/node guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5126 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5134 /root/.task/node-v20.11.1-linux-x64/bin/node delete-file write-file guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5134 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5135 /root/.task/node-v20.11.1-linux-x64/bin/node delete-file dns net send-data write-file guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5135 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5136 /root/.task/node-v20.11.1-linux-x64/bin/node delete-file write-file guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5136 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5137 /root/.task/node-v20.11.1-linux-x64/bin/node delete-file write-file guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5120->guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5137 clone guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5135->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 03a06ead-dcf2-508f-9497-1558fec78ee4 registry.npmjs.org:0 guuid=c4e13d62-1d00-0000-a171-101500140000 pid=5135->03a06ead-dcf2-508f-9497-1558fec78ee4 con
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-09-16 09:20:21 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Checks CPU configuration
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

sh 47c0d92b76fc8399a217da9e169042ee66639bb84da848e6db259736f30320b0

(this sample)

Comments