MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4f00d61599b96e6a3a184dc1c0438e6b6292ac370e152af04e6e4eee7c08488f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 7
| SHA256 hash: | 4f00d61599b96e6a3a184dc1c0438e6b6292ac370e152af04e6e4eee7c08488f |
|---|---|
| SHA3-384 hash: | d29ba5fb8adde9e0b1ad62d6a725084296f38a71d9e63f92fa66313d0f17cf70a0a527a776dffda759366c3818921468 |
| SHA1 hash: | 9d02c2980b8215bc8e4b220d28a102078eaa57fa |
| MD5 hash: | 370ab4ffb405ed48a2fb996a5ac964e3 |
| humanhash: | oscar-six-oxygen-diet |
| File name: | x |
| Download: | download sample |
| File size: | 703 bytes |
| First seen: | 2026-06-19 06:41:59 UTC |
| Last seen: | Never |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 12:hKBFKaLcLLDvTWiIjDrIMTWmgTWC6TWpdgWKy:Ar7L8WiyUMkfgWKy |
| TLSH | T1D30175CF04D618226196CEB8BFA7DC146D86EFD21CC24E0CAAC618E3508C9947836F36 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Shell script dropper
This file seems to be a shell script dropper, using wget, ftpget and/or curl. More information about the corresponding payload URLs are shown below.
| URL | Malware sample (SHA256 hash) | Signature | Tags |
|---|---|---|---|
| http://91.92.42.203/karm7 | d6a860633e869de93f1299d8b3cd7b2ce2e848ee4782093ce4265d5fe8838fc7 | Mirai | botnet mirai |
| http://91.92.42.203/karm5 | 963bab24d0fee05d712e5ca3dfe61865a85858ef0d43cee61785a1c422fb7761 | Mirai | botnet mirai |
| http://91.92.42.203/karm6 | d43ae49d93c621bdc22273954dac78d673b08241ff419057dba269a964ee1938 | Mirai | botnet mirai |
| http://91.92.42.203/karm | 45ee32938be4c01a092ea4d31d8466fa8cd84f1ee856b557cda7cb517c7850de | Mirai | botnet mirai |
Intelligence
File Origin
DEVendor Threat Intelligence
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 4f00d61599b96e6a3a184dc1c0438e6b6292ac370e152af04e6e4eee7c08488f
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.