🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d3505ab2134914e00d257f7e784f451be2bb90fd6afa09e98de003b1245fe13. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4d3505ab2134914e00d257f7e784f451be2bb90fd6afa09e98de003b1245fe13
SHA3-384 hash: fd47bbdbb38eb8036bc73ded097bbf591203ec01d17697847b2909f9b31ea438d3ab7fa6ad893c5b0185c414197f8c51
SHA1 hash: 0d4a52d0926193219c2cf5b02395bc540308a276
MD5 hash: 78094b85fba3908e511c3456cb72d828
humanhash: burger-purple-indigo-sink
File name:c8r3nv.sh
Download: download sample
File size:561 bytes
First seen:2026-09-01 12:37:27 UTC
Last seen:2026-09-02 12:23:03 UTC
File type: sh
MIME type:text/plain
ssdeep 6:SAY9PSlUyFAGyAY9CDnJjuJY9eQiASXdAY9YeyOHY9JeiN26gY9f1ivXiJh+Pn:41Gy2DJjcASXueyOdkxL9iP
TLSH T1A1F0968F252CA827740C8E4636D294046444E2CB7A5FCF847B589C2ECCD4A0DB179B7D
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.250.181.124/k7m2q9xa/q4m8azn/an/an/a
http://160.250.181.124/k7m2q9xa/r71kxpn/an/an/a
http://160.250.181.124/k7m2q9xa/t6n3wyn/an/an/a
http://160.250.181.124/k7m2q9xa/v5x92kn/an/an/a
http://160.250.181.124/k7m2q9xa/w31qhpn/an/an/a
http://160.250.181.124/k7m2q9xa/a7k2mzn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
ps1
First seen:
2026-09-01T10:49:00Z UTC
Last seen:
2026-09-02T23:51:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=76b49a15-1700-0000-a529-d469850c0000 pid=3205 /usr/bin/sudo guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206 /tmp/sample.bin guuid=76b49a15-1700-0000-a529-d469850c0000 pid=3205->guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206 execve guuid=e8717f18-1700-0000-a529-d469870c0000 pid=3207 /usr/bin/wget net send-data write-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=e8717f18-1700-0000-a529-d469870c0000 pid=3207 execve guuid=46842a48-1700-0000-a529-d469cb0c0000 pid=3275 /usr/bin/chmod guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=46842a48-1700-0000-a529-d469cb0c0000 pid=3275 execve guuid=ee0a6e48-1700-0000-a529-d469cd0c0000 pid=3277 /usr/bin/dash guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=ee0a6e48-1700-0000-a529-d469cd0c0000 pid=3277 clone guuid=f4071349-1700-0000-a529-d469d00c0000 pid=3280 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=f4071349-1700-0000-a529-d469d00c0000 pid=3280 execve guuid=e1267549-1700-0000-a529-d469d10c0000 pid=3281 /usr/bin/wget net send-data write-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=e1267549-1700-0000-a529-d469d10c0000 pid=3281 execve guuid=208fd873-1700-0000-a529-d469290d0000 pid=3369 /usr/bin/chmod guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=208fd873-1700-0000-a529-d469290d0000 pid=3369 execve guuid=d56f2674-1700-0000-a529-d4692b0d0000 pid=3371 /usr/bin/dash guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=d56f2674-1700-0000-a529-d4692b0d0000 pid=3371 clone guuid=1239cf74-1700-0000-a529-d4692f0d0000 pid=3375 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=1239cf74-1700-0000-a529-d4692f0d0000 pid=3375 execve guuid=3a0d2475-1700-0000-a529-d469340d0000 pid=3380 /usr/bin/wget net send-data write-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=3a0d2475-1700-0000-a529-d469340d0000 pid=3380 execve guuid=1b85919d-1700-0000-a529-d469820d0000 pid=3458 /usr/bin/chmod guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=1b85919d-1700-0000-a529-d469820d0000 pid=3458 execve guuid=847ff29d-1700-0000-a529-d469830d0000 pid=3459 /usr/bin/dash guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=847ff29d-1700-0000-a529-d469830d0000 pid=3459 clone guuid=f7ba289f-1700-0000-a529-d469880d0000 pid=3464 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=f7ba289f-1700-0000-a529-d469880d0000 pid=3464 execve guuid=92e0869f-1700-0000-a529-d469890d0000 pid=3465 /usr/bin/wget net send-data write-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=92e0869f-1700-0000-a529-d469890d0000 pid=3465 execve guuid=2bb2dbc6-1700-0000-a529-d469f00d0000 pid=3568 /usr/bin/chmod guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=2bb2dbc6-1700-0000-a529-d469f00d0000 pid=3568 execve guuid=94101ac7-1700-0000-a529-d469f20d0000 pid=3570 /usr/bin/dash guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=94101ac7-1700-0000-a529-d469f20d0000 pid=3570 clone guuid=cfffa7c8-1700-0000-a529-d469f40d0000 pid=3572 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=cfffa7c8-1700-0000-a529-d469f40d0000 pid=3572 execve guuid=7c2305c9-1700-0000-a529-d469f50d0000 pid=3573 /usr/bin/wget net send-data write-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=7c2305c9-1700-0000-a529-d469f50d0000 pid=3573 execve guuid=1fc5a9f1-1700-0000-a529-d469890e0000 pid=3721 /usr/bin/chmod guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=1fc5a9f1-1700-0000-a529-d469890e0000 pid=3721 execve guuid=d0c8e4f1-1700-0000-a529-d4698b0e0000 pid=3723 /usr/bin/dash guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=d0c8e4f1-1700-0000-a529-d4698b0e0000 pid=3723 clone guuid=bcd738f3-1700-0000-a529-d469900e0000 pid=3728 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=bcd738f3-1700-0000-a529-d469900e0000 pid=3728 execve guuid=5f817af3-1700-0000-a529-d469920e0000 pid=3730 /usr/bin/wget net send-data write-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=5f817af3-1700-0000-a529-d469920e0000 pid=3730 execve guuid=cbeac121-1800-0000-a529-d4693b0f0000 pid=3899 /usr/bin/chmod guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=cbeac121-1800-0000-a529-d4693b0f0000 pid=3899 execve guuid=21ca0022-1800-0000-a529-d4693c0f0000 pid=3900 /usr/bin/dash guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=21ca0022-1800-0000-a529-d4693c0f0000 pid=3900 clone guuid=752d0e22-1800-0000-a529-d4693f0f0000 pid=3903 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=752d0e22-1800-0000-a529-d4693f0f0000 pid=3903 execve guuid=a1b74a22-1800-0000-a529-d469410f0000 pid=3905 /usr/bin/rm delete-file guuid=e6812618-1700-0000-a529-d469860c0000 pid=3206->guuid=a1b74a22-1800-0000-a529-d469410f0000 pid=3905 execve 41810b37-cfe3-5e1b-81e2-1800bf1431b3 160.250.181.124:80 guuid=e8717f18-1700-0000-a529-d469870c0000 pid=3207->41810b37-cfe3-5e1b-81e2-1800bf1431b3 send: 145B guuid=e1267549-1700-0000-a529-d469d10c0000 pid=3281->41810b37-cfe3-5e1b-81e2-1800bf1431b3 send: 145B guuid=3a0d2475-1700-0000-a529-d469340d0000 pid=3380->41810b37-cfe3-5e1b-81e2-1800bf1431b3 send: 145B guuid=92e0869f-1700-0000-a529-d469890d0000 pid=3465->41810b37-cfe3-5e1b-81e2-1800bf1431b3 send: 145B guuid=7c2305c9-1700-0000-a529-d469f50d0000 pid=3573->41810b37-cfe3-5e1b-81e2-1800bf1431b3 send: 145B guuid=5f817af3-1700-0000-a529-d469920e0000 pid=3730->41810b37-cfe3-5e1b-81e2-1800bf1431b3 send: 145B
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-01 12:38:43 UTC
File Type:
Text (Shell)
AV detection:
13 of 38 (34.21%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4d3505ab2134914e00d257f7e784f451be2bb90fd6afa09e98de003b1245fe13

(this sample)

  
Delivery method
Distributed via web download

Comments