MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4963296d9dc512a2b37419399b91ab345163e924f5a28d9e3bae5aac8126e752. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4963296d9dc512a2b37419399b91ab345163e924f5a28d9e3bae5aac8126e752
SHA3-384 hash: a83eebdcaf9bad257bbec9149e384b7607394a1fb778d59bff256b4dc7d73fadd471154d2887fccfc5f8fc84d0f2bf77
SHA1 hash: d1ad69512b6bc9d157e891d629677eb3a84a15e8
MD5 hash: 06f6e8dd3b5a1d0f984b1e8812df1fb1
humanhash: massachusetts-king-robin-kilo
File name:telnet.sh
Download: download sample
File size:1'694 bytes
First seen:2025-08-03 00:00:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:RPf/n0BvBoF1zcDzD/38PQkwChNIJttUTaJfVGLYnvEPA7C:UYWrzM
TLSH T1343168CD1EE051D2C980CE29B2734F88A049D5C822FA8A73BCC5BC71DB49EC0B857E16
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://92.113.21.114/x86_64n/an/aelf ua-wget
http://92.113.21.114/aarch64n/an/aelf ua-wget
http://92.113.21.114/m68kn/an/aelf ua-wget
http://92.113.21.114/mipsn/an/aelf ua-wget
http://92.113.21.114/mipseln/an/aelf ua-wget
http://92.113.21.114/powerpcn/an/aelf ua-wget
http://92.113.21.114/sparcn/an/aelf ua-wget
http://92.113.21.114/sh4n/an/aelf ua-wget
http://92.113.21.114/arcn/an/aelf ua-wget
http://92.113.21.114/i486n/an/aelf ua-wget
http://92.113.21.114/armv4ln/an/aelf ua-wget
http://92.113.21.114/armv5ln/an/aelf ua-wget
http://92.113.21.114/armv6ln/an/aelf ua-wget
http://92.113.21.114/armv7ln/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=2d132900-1700-0000-f294-eca3630d0000 pid=3427 /usr/bin/sudo guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434 /tmp/sample.bin guuid=2d132900-1700-0000-f294-eca3630d0000 pid=3427->guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434 execve guuid=04248602-1700-0000-f294-eca36c0d0000 pid=3436 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=04248602-1700-0000-f294-eca36c0d0000 pid=3436 execve guuid=859c1706-1700-0000-f294-eca3780d0000 pid=3448 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=859c1706-1700-0000-f294-eca3780d0000 pid=3448 execve guuid=1d74380c-1700-0000-f294-eca38a0d0000 pid=3466 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=1d74380c-1700-0000-f294-eca38a0d0000 pid=3466 execve guuid=27ee790c-1700-0000-f294-eca38b0d0000 pid=3467 /home/sandbox/x86_64 guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=27ee790c-1700-0000-f294-eca38b0d0000 pid=3467 execve guuid=88694e0e-1700-0000-f294-eca3910d0000 pid=3473 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=88694e0e-1700-0000-f294-eca3910d0000 pid=3473 execve guuid=01f24f11-1700-0000-f294-eca39a0d0000 pid=3482 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=01f24f11-1700-0000-f294-eca39a0d0000 pid=3482 execve guuid=e5f1df14-1700-0000-f294-eca3a50d0000 pid=3493 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e5f1df14-1700-0000-f294-eca3a50d0000 pid=3493 execve guuid=2a692d15-1700-0000-f294-eca3a60d0000 pid=3494 /home/sandbox/aarch64 guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=2a692d15-1700-0000-f294-eca3a60d0000 pid=3494 execve guuid=e2167d15-1700-0000-f294-eca3a70d0000 pid=3495 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e2167d15-1700-0000-f294-eca3a70d0000 pid=3495 execve guuid=25de5317-1700-0000-f294-eca3a80d0000 pid=3496 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=25de5317-1700-0000-f294-eca3a80d0000 pid=3496 execve guuid=da19a41a-1700-0000-f294-eca3a90d0000 pid=3497 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=da19a41a-1700-0000-f294-eca3a90d0000 pid=3497 execve guuid=068bea1a-1700-0000-f294-eca3ad0d0000 pid=3501 /home/sandbox/m68k guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=068bea1a-1700-0000-f294-eca3ad0d0000 pid=3501 execve guuid=8d9a3d1b-1700-0000-f294-eca3ae0d0000 pid=3502 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=8d9a3d1b-1700-0000-f294-eca3ae0d0000 pid=3502 execve guuid=36117520-1700-0000-f294-eca3ba0d0000 pid=3514 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=36117520-1700-0000-f294-eca3ba0d0000 pid=3514 execve guuid=23f5eb24-1700-0000-f294-eca3c70d0000 pid=3527 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=23f5eb24-1700-0000-f294-eca3c70d0000 pid=3527 execve guuid=eb1a4a25-1700-0000-f294-eca3c90d0000 pid=3529 /home/sandbox/mips guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=eb1a4a25-1700-0000-f294-eca3c90d0000 pid=3529 execve guuid=e9259025-1700-0000-f294-eca3ca0d0000 pid=3530 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e9259025-1700-0000-f294-eca3ca0d0000 pid=3530 execve guuid=a4e09d28-1700-0000-f294-eca3d40d0000 pid=3540 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=a4e09d28-1700-0000-f294-eca3d40d0000 pid=3540 execve guuid=197f852c-1700-0000-f294-eca3dd0d0000 pid=3549 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=197f852c-1700-0000-f294-eca3dd0d0000 pid=3549 execve guuid=cceeb52c-1700-0000-f294-eca3df0d0000 pid=3551 /home/sandbox/mipsel guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=cceeb52c-1700-0000-f294-eca3df0d0000 pid=3551 execve guuid=6378e62c-1700-0000-f294-eca3e10d0000 pid=3553 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=6378e62c-1700-0000-f294-eca3e10d0000 pid=3553 execve guuid=8cd65b2e-1700-0000-f294-eca3e80d0000 pid=3560 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=8cd65b2e-1700-0000-f294-eca3e80d0000 pid=3560 execve guuid=fc918e30-1700-0000-f294-eca3f30d0000 pid=3571 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=fc918e30-1700-0000-f294-eca3f30d0000 pid=3571 execve guuid=7b28c330-1700-0000-f294-eca3f50d0000 pid=3573 /home/sandbox/powerpc guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=7b28c330-1700-0000-f294-eca3f50d0000 pid=3573 execve guuid=2434f230-1700-0000-f294-eca3f60d0000 pid=3574 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=2434f230-1700-0000-f294-eca3f60d0000 pid=3574 execve guuid=3b206332-1700-0000-f294-eca3fe0d0000 pid=3582 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=3b206332-1700-0000-f294-eca3fe0d0000 pid=3582 execve guuid=e42cc834-1700-0000-f294-eca3050e0000 pid=3589 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e42cc834-1700-0000-f294-eca3050e0000 pid=3589 execve guuid=e32b1c35-1700-0000-f294-eca3070e0000 pid=3591 /home/sandbox/sparc guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e32b1c35-1700-0000-f294-eca3070e0000 pid=3591 execve guuid=f86f7935-1700-0000-f294-eca3090e0000 pid=3593 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=f86f7935-1700-0000-f294-eca3090e0000 pid=3593 execve guuid=4b566f37-1700-0000-f294-eca3100e0000 pid=3600 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=4b566f37-1700-0000-f294-eca3100e0000 pid=3600 execve guuid=d691b139-1700-0000-f294-eca3170e0000 pid=3607 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=d691b139-1700-0000-f294-eca3170e0000 pid=3607 execve guuid=0a70e639-1700-0000-f294-eca3180e0000 pid=3608 /home/sandbox/sh4 guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=0a70e639-1700-0000-f294-eca3180e0000 pid=3608 execve guuid=fdf9233a-1700-0000-f294-eca31a0e0000 pid=3610 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=fdf9233a-1700-0000-f294-eca31a0e0000 pid=3610 execve guuid=e16ed03b-1700-0000-f294-eca3210e0000 pid=3617 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e16ed03b-1700-0000-f294-eca3210e0000 pid=3617 execve guuid=c950133e-1700-0000-f294-eca3280e0000 pid=3624 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=c950133e-1700-0000-f294-eca3280e0000 pid=3624 execve guuid=d586563e-1700-0000-f294-eca32a0e0000 pid=3626 /home/sandbox/arc guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=d586563e-1700-0000-f294-eca32a0e0000 pid=3626 execve guuid=7ad98f3e-1700-0000-f294-eca32b0e0000 pid=3627 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=7ad98f3e-1700-0000-f294-eca32b0e0000 pid=3627 execve guuid=c8253a40-1700-0000-f294-eca3310e0000 pid=3633 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=c8253a40-1700-0000-f294-eca3310e0000 pid=3633 execve guuid=022dec43-1700-0000-f294-eca3340e0000 pid=3636 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=022dec43-1700-0000-f294-eca3340e0000 pid=3636 execve guuid=26c85744-1700-0000-f294-eca3350e0000 pid=3637 /home/sandbox/i486 guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=26c85744-1700-0000-f294-eca3350e0000 pid=3637 execve guuid=2e159844-1700-0000-f294-eca3360e0000 pid=3638 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=2e159844-1700-0000-f294-eca3360e0000 pid=3638 execve guuid=7738db46-1700-0000-f294-eca3370e0000 pid=3639 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=7738db46-1700-0000-f294-eca3370e0000 pid=3639 execve guuid=7945b44a-1700-0000-f294-eca3460e0000 pid=3654 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=7945b44a-1700-0000-f294-eca3460e0000 pid=3654 execve guuid=9b66ea4a-1700-0000-f294-eca3470e0000 pid=3655 /home/sandbox/armv4l guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=9b66ea4a-1700-0000-f294-eca3470e0000 pid=3655 execve guuid=2d15564b-1700-0000-f294-eca3490e0000 pid=3657 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=2d15564b-1700-0000-f294-eca3490e0000 pid=3657 execve guuid=af66d94d-1700-0000-f294-eca3550e0000 pid=3669 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=af66d94d-1700-0000-f294-eca3550e0000 pid=3669 execve guuid=e12f2950-1700-0000-f294-eca35a0e0000 pid=3674 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e12f2950-1700-0000-f294-eca35a0e0000 pid=3674 execve guuid=9e509550-1700-0000-f294-eca35c0e0000 pid=3676 /home/sandbox/armv5l guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=9e509550-1700-0000-f294-eca35c0e0000 pid=3676 execve guuid=2eefcb50-1700-0000-f294-eca35e0e0000 pid=3678 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=2eefcb50-1700-0000-f294-eca35e0e0000 pid=3678 execve guuid=5e216c52-1700-0000-f294-eca3640e0000 pid=3684 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=5e216c52-1700-0000-f294-eca3640e0000 pid=3684 execve guuid=3853b854-1700-0000-f294-eca36b0e0000 pid=3691 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=3853b854-1700-0000-f294-eca36b0e0000 pid=3691 execve guuid=2fb9f254-1700-0000-f294-eca36c0e0000 pid=3692 /usr/bin/dash guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=2fb9f254-1700-0000-f294-eca36c0e0000 pid=3692 clone guuid=11f22b55-1700-0000-f294-eca36e0e0000 pid=3694 /usr/bin/wget net send-data guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=11f22b55-1700-0000-f294-eca36e0e0000 pid=3694 execve guuid=ed640157-1700-0000-f294-eca3730e0000 pid=3699 /usr/bin/curl net send-data write-file guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=ed640157-1700-0000-f294-eca3730e0000 pid=3699 execve guuid=e4619d59-1700-0000-f294-eca3800e0000 pid=3712 /usr/bin/chmod guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=e4619d59-1700-0000-f294-eca3800e0000 pid=3712 execve guuid=95c1e959-1700-0000-f294-eca3810e0000 pid=3713 /home/sandbox/armv7l guuid=03584202-1700-0000-f294-eca36a0d0000 pid=3434->guuid=95c1e959-1700-0000-f294-eca3810e0000 pid=3713 execve 03049f1c-3998-5687-aced-c03ba7d5d14f 92.113.21.114:80 guuid=04248602-1700-0000-f294-eca36c0d0000 pid=3436->03049f1c-3998-5687-aced-c03ba7d5d14f send: 134B guuid=859c1706-1700-0000-f294-eca3780d0000 pid=3448->03049f1c-3998-5687-aced-c03ba7d5d14f send: 83B guuid=88694e0e-1700-0000-f294-eca3910d0000 pid=3473->03049f1c-3998-5687-aced-c03ba7d5d14f send: 135B guuid=01f24f11-1700-0000-f294-eca39a0d0000 pid=3482->03049f1c-3998-5687-aced-c03ba7d5d14f send: 84B guuid=e2167d15-1700-0000-f294-eca3a70d0000 pid=3495->03049f1c-3998-5687-aced-c03ba7d5d14f send: 132B guuid=25de5317-1700-0000-f294-eca3a80d0000 pid=3496->03049f1c-3998-5687-aced-c03ba7d5d14f send: 81B guuid=8d9a3d1b-1700-0000-f294-eca3ae0d0000 pid=3502->03049f1c-3998-5687-aced-c03ba7d5d14f send: 132B guuid=36117520-1700-0000-f294-eca3ba0d0000 pid=3514->03049f1c-3998-5687-aced-c03ba7d5d14f send: 81B guuid=e9259025-1700-0000-f294-eca3ca0d0000 pid=3530->03049f1c-3998-5687-aced-c03ba7d5d14f send: 134B guuid=a4e09d28-1700-0000-f294-eca3d40d0000 pid=3540->03049f1c-3998-5687-aced-c03ba7d5d14f send: 83B guuid=6378e62c-1700-0000-f294-eca3e10d0000 pid=3553->03049f1c-3998-5687-aced-c03ba7d5d14f send: 135B guuid=8cd65b2e-1700-0000-f294-eca3e80d0000 pid=3560->03049f1c-3998-5687-aced-c03ba7d5d14f send: 84B guuid=2434f230-1700-0000-f294-eca3f60d0000 pid=3574->03049f1c-3998-5687-aced-c03ba7d5d14f send: 133B guuid=3b206332-1700-0000-f294-eca3fe0d0000 pid=3582->03049f1c-3998-5687-aced-c03ba7d5d14f send: 82B guuid=f86f7935-1700-0000-f294-eca3090e0000 pid=3593->03049f1c-3998-5687-aced-c03ba7d5d14f send: 131B guuid=4b566f37-1700-0000-f294-eca3100e0000 pid=3600->03049f1c-3998-5687-aced-c03ba7d5d14f send: 80B guuid=fdf9233a-1700-0000-f294-eca31a0e0000 pid=3610->03049f1c-3998-5687-aced-c03ba7d5d14f send: 131B guuid=e16ed03b-1700-0000-f294-eca3210e0000 pid=3617->03049f1c-3998-5687-aced-c03ba7d5d14f send: 80B guuid=7ad98f3e-1700-0000-f294-eca32b0e0000 pid=3627->03049f1c-3998-5687-aced-c03ba7d5d14f send: 132B guuid=c8253a40-1700-0000-f294-eca3310e0000 pid=3633->03049f1c-3998-5687-aced-c03ba7d5d14f send: 81B guuid=2e159844-1700-0000-f294-eca3360e0000 pid=3638->03049f1c-3998-5687-aced-c03ba7d5d14f send: 134B guuid=7738db46-1700-0000-f294-eca3370e0000 pid=3639->03049f1c-3998-5687-aced-c03ba7d5d14f send: 83B guuid=2d15564b-1700-0000-f294-eca3490e0000 pid=3657->03049f1c-3998-5687-aced-c03ba7d5d14f send: 134B guuid=af66d94d-1700-0000-f294-eca3550e0000 pid=3669->03049f1c-3998-5687-aced-c03ba7d5d14f send: 83B guuid=2eefcb50-1700-0000-f294-eca35e0e0000 pid=3678->03049f1c-3998-5687-aced-c03ba7d5d14f send: 134B guuid=5e216c52-1700-0000-f294-eca3640e0000 pid=3684->03049f1c-3998-5687-aced-c03ba7d5d14f send: 83B guuid=11f22b55-1700-0000-f294-eca36e0e0000 pid=3694->03049f1c-3998-5687-aced-c03ba7d5d14f send: 134B guuid=ed640157-1700-0000-f294-eca3730e0000 pid=3699->03049f1c-3998-5687-aced-c03ba7d5d14f send: 83B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-08-03 00:01:11 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4963296d9dc512a2b37419399b91ab345163e924f5a28d9e3bae5aac8126e752

(this sample)

  
Delivery method
Distributed via web download

Comments