MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 494c77d50b04bc0d2a9d9fc752af97c77949788c92e2d1fffacda5c2bf8cf3d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 494c77d50b04bc0d2a9d9fc752af97c77949788c92e2d1fffacda5c2bf8cf3d9
SHA3-384 hash: 9d7d3ee7cc5fdda4a2eb68ca648d286f90bfbf19a7ed6d39cd76985fac75ba354809b04bc7bea0dc47d64d1d1130a229
SHA1 hash: b9304f0cdc1afb982e058abc4d89f26b29ff64c3
MD5 hash: 5ffcf0b2cc2f34f9f0319e4d68f4104f
humanhash: bluebird-fanta-nevada-floor
File name:cat.sh
Download: download sample
File size:1'842 bytes
First seen:2026-05-24 18:35:04 UTC
Last seen:2026-05-25 16:02:02 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:719pNq9lM4U+6+y9k0g8uP8wenaktTbM2w:719pNq9W4aPHtTbS
TLSH T117318EEEBC60D073314D983AE54DB2112B8725DF11A03E0978938B715E2D958F8BDBE6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.107/n/an/an/a
http://blacknigger.boo/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
44
Origin country :
US US
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=f99d8801-1700-0000-11a9-9fffb4090000 pid=2484 /usr/bin/sudo guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485 /tmp/sample.bin write-file guuid=f99d8801-1700-0000-11a9-9fffb4090000 pid=2484->guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485 execve guuid=e1e0a604-1700-0000-11a9-9fffb6090000 pid=2486 /usr/bin/grep guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=e1e0a604-1700-0000-11a9-9fffb6090000 pid=2486 execve guuid=3bd71b05-1700-0000-11a9-9fffb7090000 pid=2487 /usr/bin/uname guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=3bd71b05-1700-0000-11a9-9fffb7090000 pid=2487 execve guuid=1bb38b05-1700-0000-11a9-9fffb8090000 pid=2488 /usr/bin/wget dns net send-data write-file guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=1bb38b05-1700-0000-11a9-9fffb8090000 pid=2488 execve guuid=0dc4d687-1700-0000-11a9-9fffe1090000 pid=2529 /usr/bin/chmod guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=0dc4d687-1700-0000-11a9-9fffe1090000 pid=2529 execve guuid=139d1b88-1700-0000-11a9-9fffe3090000 pid=2531 /usr/bin/dash guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=139d1b88-1700-0000-11a9-9fffe3090000 pid=2531 execve guuid=a1096188-1700-0000-11a9-9fffe5090000 pid=2533 /usr/bin/dash guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=a1096188-1700-0000-11a9-9fffe5090000 pid=2533 execve guuid=d250aa88-1700-0000-11a9-9fffe7090000 pid=2535 /usr/bin/busybox guuid=13b34004-1700-0000-11a9-9fffb5090000 pid=2485->guuid=d250aa88-1700-0000-11a9-9fffe7090000 pid=2535 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1bb38b05-1700-0000-11a9-9fffb8090000 pid=2488->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 66B 2c96f5ef-0da3-5fe3-adec-8e6845474be1 blacknigger.boo:80 guuid=1bb38b05-1700-0000-11a9-9fffb8090000 pid=2488->2c96f5ef-0da3-5fe3-adec-8e6845474be1 send: 137B
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 494c77d50b04bc0d2a9d9fc752af97c77949788c92e2d1fffacda5c2bf8cf3d9

(this sample)

  
Delivery method
Distributed via web download

Comments