MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4c5f76816548a45703d8b3a8f047bc05d5bfcec20e3db1dad423a3c503cf76cd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4c5f76816548a45703d8b3a8f047bc05d5bfcec20e3db1dad423a3c503cf76cd
SHA3-384 hash: dea983c392ce78df30947b82b2a109825ff88edbf78d709e3009c6d4bc65a8caa71e81b45d3afe8907af801debe544c8
SHA1 hash: b69e0f8d0254e37e0ee23e5639c9d6998133855e
MD5 hash: 7e0a526d2bc04bd5d332591cbee569ca
humanhash: edward-solar-emma-undress
File name:install_panel.sh
Download: download sample
File size:79'133 bytes
First seen:2026-08-13 07:32:02 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 1536:7HKhEb5evVnosI9fsQyeSxXeg+nhLh8xLjfhQH7hrt4sCaW9mpWpMr6jW+56yZdH:jxb2VnosI9fsQyeSxXeg+nhLh8xLjfhT
TLSH T18B730896EF08C9F43C50C22E5B518E4DFA0FA2D702157864B0DEB8A42B5CB73B97D616
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://www.bt.cn/api/wpanel/SetupCountn/an/an/a
https://api.bt.cn/api/isCNn/an/an/a
https://mirrors.aliyun.com/repo/Centos-vault-8.5.2111.repon/an/an/a
https://mirrors.aliyun.com/repo/epel-archive-8.repon/an/an/a
http://download.bt.cn/install/yumRepo_select.shn/an/an/a
https://www.bt.cn/api/index/get_timen/an/an/a
https://download.bt.cn/install/plugin/oneav/install.shn/an/an/a
https://www.bt.cn/Api/getIpAddressn/an/an/a
https://api.bt.cn/Api/getIpAddressn/an/an/a
https://www.aapanel.com/api/common/getClientIPn/an/an/a
https://www.bt.cn/Api/SetupCountn/an/an/a
https://www.bt.cn/Api/SetupCountPren/an/an/a
https://www.bt.cn/Api/installationCountn/an/an/a
https://www-node3.bt.cn/Api/installationCountn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash lolbin opendir
Status:
terminated
Behavior Graph:
%3 guuid=22323ad1-1800-0000-c10e-17713e0d0000 pid=3390 /usr/bin/sudo guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401 /tmp/sample.bin guuid=22323ad1-1800-0000-c10e-17713e0d0000 pid=3390->guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401 execve guuid=b1e3d8d7-1800-0000-c10e-17714d0d0000 pid=3405 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=b1e3d8d7-1800-0000-c10e-17714d0d0000 pid=3405 clone guuid=be6a2ed9-1800-0000-c10e-1771530d0000 pid=3411 /usr/bin/tee write-file guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=be6a2ed9-1800-0000-c10e-1771530d0000 pid=3411 execve guuid=e24b3dd9-1800-0000-c10e-1771540d0000 pid=3412 /usr/bin/which.debianutils guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=e24b3dd9-1800-0000-c10e-1771540d0000 pid=3412 execve guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3413 /usr/bin/curl net send-data guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3413 execve guuid=da387321-1900-0000-c10e-1771dd0d0000 pid=3549 /usr/bin/whoami guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=da387321-1900-0000-c10e-1771dd0d0000 pid=3549 execve guuid=3fe12822-1900-0000-c10e-1771de0d0000 pid=3550 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=3fe12822-1900-0000-c10e-1771de0d0000 pid=3550 clone guuid=b76d9024-1900-0000-c10e-1771e20d0000 pid=3554 /usr/bin/getconf guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=b76d9024-1900-0000-c10e-1771e20d0000 pid=3554 execve guuid=e4b62525-1900-0000-c10e-1771e30d0000 pid=3555 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=e4b62525-1900-0000-c10e-1771e30d0000 pid=3555 clone guuid=8ed57026-1900-0000-c10e-1771ed0d0000 pid=3565 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=8ed57026-1900-0000-c10e-1771ed0d0000 pid=3565 clone guuid=a2aa9327-1900-0000-c10e-1771f60d0000 pid=3574 /usr/bin/cat guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=a2aa9327-1900-0000-c10e-1771f60d0000 pid=3574 execve guuid=0b381428-1900-0000-c10e-1771f90d0000 pid=3577 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=0b381428-1900-0000-c10e-1771f90d0000 pid=3577 clone guuid=d14f422a-1900-0000-c10e-1771fd0d0000 pid=3581 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=d14f422a-1900-0000-c10e-1771fd0d0000 pid=3581 clone guuid=4a36842b-1900-0000-c10e-1771010e0000 pid=3585 /usr/bin/bash guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=4a36842b-1900-0000-c10e-1771010e0000 pid=3585 clone guuid=0569a92f-1900-0000-c10e-17710f0e0000 pid=3599 /usr/bin/expr guuid=5f8042d6-1800-0000-c10e-1771490d0000 pid=3401->guuid=0569a92f-1900-0000-c10e-17710f0e0000 pid=3599 execve guuid=04d846d8-1800-0000-c10e-17714f0d0000 pid=3407 /usr/bin/uname guuid=b1e3d8d7-1800-0000-c10e-17714d0d0000 pid=3405->guuid=04d846d8-1800-0000-c10e-17714f0d0000 pid=3407 execve guuid=753c85d8-1800-0000-c10e-1771500d0000 pid=3408 /usr/bin/grep guuid=b1e3d8d7-1800-0000-c10e-17714d0d0000 pid=3405->guuid=753c85d8-1800-0000-c10e-1771500d0000 pid=3408 execve 83ee29da-e6c1-5782-beaf-7dee6832de76 www.bt.cn:443 guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3413->83ee29da-e6c1-5782-beaf-7dee6832de76 send: 789B guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3417 /usr/bin/curl dns net send-data guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3413->guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3417 clone guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3417->83ee29da-e6c1-5782-beaf-7dee6832de76 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=405d89da-1800-0000-c10e-1771550d0000 pid=3417->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 54B guuid=228b4522-1900-0000-c10e-1771df0d0000 pid=3551 /usr/bin/free guuid=3fe12822-1900-0000-c10e-1771de0d0000 pid=3550->guuid=228b4522-1900-0000-c10e-1771df0d0000 pid=3551 execve guuid=c4185022-1900-0000-c10e-1771e00d0000 pid=3552 /usr/bin/grep guuid=3fe12822-1900-0000-c10e-1771de0d0000 pid=3550->guuid=c4185022-1900-0000-c10e-1771e00d0000 pid=3552 execve guuid=45515922-1900-0000-c10e-1771e10d0000 pid=3553 /usr/bin/mawk guuid=3fe12822-1900-0000-c10e-1771de0d0000 pid=3550->guuid=45515922-1900-0000-c10e-1771e10d0000 pid=3553 execve guuid=d73b3e25-1900-0000-c10e-1771e60d0000 pid=3558 /usr/bin/cat guuid=e4b62525-1900-0000-c10e-1771e30d0000 pid=3555->guuid=d73b3e25-1900-0000-c10e-1771e60d0000 pid=3558 execve guuid=43344b25-1900-0000-c10e-1771e80d0000 pid=3560 /usr/bin/grep guuid=e4b62525-1900-0000-c10e-1771e30d0000 pid=3555->guuid=43344b25-1900-0000-c10e-1771e80d0000 pid=3560 execve guuid=fc086625-1900-0000-c10e-1771e90d0000 pid=3561 /usr/bin/grep guuid=e4b62525-1900-0000-c10e-1771e30d0000 pid=3555->guuid=fc086625-1900-0000-c10e-1771e90d0000 pid=3561 execve guuid=fa817c26-1900-0000-c10e-1771ee0d0000 pid=3566 /usr/bin/cat guuid=8ed57026-1900-0000-c10e-1771ed0d0000 pid=3565->guuid=fa817c26-1900-0000-c10e-1771ee0d0000 pid=3566 execve guuid=cd888526-1900-0000-c10e-1771f00d0000 pid=3568 /usr/bin/grep guuid=8ed57026-1900-0000-c10e-1771ed0d0000 pid=3565->guuid=cd888526-1900-0000-c10e-1771f00d0000 pid=3568 execve guuid=3d9b8a26-1900-0000-c10e-1771f10d0000 pid=3569 /usr/bin/mawk guuid=8ed57026-1900-0000-c10e-1771ed0d0000 pid=3565->guuid=3d9b8a26-1900-0000-c10e-1771f10d0000 pid=3569 execve guuid=37388f26-1900-0000-c10e-1771f20d0000 pid=3570 /usr/bin/cut guuid=8ed57026-1900-0000-c10e-1771ed0d0000 pid=3565->guuid=37388f26-1900-0000-c10e-1771f20d0000 pid=3570 execve guuid=ccc42128-1900-0000-c10e-1771fa0d0000 pid=3578 /usr/bin/cat guuid=0b381428-1900-0000-c10e-1771f90d0000 pid=3577->guuid=ccc42128-1900-0000-c10e-1771fa0d0000 pid=3578 execve guuid=16973128-1900-0000-c10e-1771fb0d0000 pid=3579 /usr/bin/grep guuid=0b381428-1900-0000-c10e-1771f90d0000 pid=3577->guuid=16973128-1900-0000-c10e-1771fb0d0000 pid=3579 execve guuid=ade33628-1900-0000-c10e-1771fc0d0000 pid=3580 /usr/bin/grep guuid=0b381428-1900-0000-c10e-1771f90d0000 pid=3577->guuid=ade33628-1900-0000-c10e-1771fc0d0000 pid=3580 execve guuid=b073652a-1900-0000-c10e-1771fe0d0000 pid=3582 /usr/bin/cat guuid=d14f422a-1900-0000-c10e-1771fd0d0000 pid=3581->guuid=b073652a-1900-0000-c10e-1771fe0d0000 pid=3582 execve guuid=1e636e2a-1900-0000-c10e-1771ff0d0000 pid=3583 /usr/bin/grep guuid=d14f422a-1900-0000-c10e-1771fd0d0000 pid=3581->guuid=1e636e2a-1900-0000-c10e-1771ff0d0000 pid=3583 execve guuid=a0a47d2a-1900-0000-c10e-1771000e0000 pid=3584 /usr/bin/grep guuid=d14f422a-1900-0000-c10e-1771fd0d0000 pid=3581->guuid=a0a47d2a-1900-0000-c10e-1771000e0000 pid=3584 execve guuid=52c7932b-1900-0000-c10e-1771020e0000 pid=3586 /usr/bin/cat guuid=4a36842b-1900-0000-c10e-1771010e0000 pid=3585->guuid=52c7932b-1900-0000-c10e-1771020e0000 pid=3586 execve guuid=0bf19c2b-1900-0000-c10e-1771030e0000 pid=3587 /usr/bin/grep guuid=4a36842b-1900-0000-c10e-1771010e0000 pid=3585->guuid=0bf19c2b-1900-0000-c10e-1771030e0000 pid=3587 execve guuid=11d6a52b-1900-0000-c10e-1771040e0000 pid=3588 /usr/bin/wc guuid=4a36842b-1900-0000-c10e-1771010e0000 pid=3585->guuid=11d6a52b-1900-0000-c10e-1771040e0000 pid=3588 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-13 07:32:32 UTC
File Type:
Text (Shell)
AV detection:
6 of 23 (26.09%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4c5f76816548a45703d8b3a8f047bc05d5bfcec20e3db1dad423a3c503cf76cd

(this sample)

  
Delivery method
Distributed via web download

Comments