MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 494c77d50b04bc0d2a9d9fc752af97c77949788c92e2d1fffacda5c2bf8cf3d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 3
| SHA256 hash: | 494c77d50b04bc0d2a9d9fc752af97c77949788c92e2d1fffacda5c2bf8cf3d9 |
|---|---|
| SHA3-384 hash: | 9d7d3ee7cc5fdda4a2eb68ca648d286f90bfbf19a7ed6d39cd76985fac75ba354809b04bc7bea0dc47d64d1d1130a229 |
| SHA1 hash: | b9304f0cdc1afb982e058abc4d89f26b29ff64c3 |
| MD5 hash: | 5ffcf0b2cc2f34f9f0319e4d68f4104f |
| humanhash: | bluebird-fanta-nevada-floor |
| File name: | cat.sh |
| Download: | download sample |
| File size: | 1'842 bytes |
| First seen: | 2026-05-24 18:35:04 UTC |
| Last seen: | 2026-05-25 16:02:02 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 48:719pNq9lM4U+6+y9k0g8uP8wenaktTbM2w:719pNq9W4aPHtTbS |
| TLSH | T117318EEEBC60D073314D983AE54DB2112B8725DF11A03E0978938B715E2D958F8BDBE6 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://176.65.139.107/ | n/a | n/a | n/a |
| http://blacknigger.boo/ | n/a | n/a | n/a |
Intelligence
File Origin
# of uploads :
2
# of downloads :
44
Origin country :
USVendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
Script
Status:
terminated
Behavior Graph:
Score:
25%
Verdict:
Benign
File Type:
SCRIPT
Verdict:
Malicious
Threat:
NetTool.Wget.HTTP
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.08
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 494c77d50b04bc0d2a9d9fc752af97c77949788c92e2d1fffacda5c2bf8cf3d9
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.