MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fbb1ebdae240e9a784ff893b113fe3244945ab322b4e733baa13a1a309ee4bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 4fbb1ebdae240e9a784ff893b113fe3244945ab322b4e733baa13a1a309ee4bf
SHA3-384 hash: 9d990a33361058f6826e5a84823be0ff007c60c711a1d3cc0c91f6b4d895316b8d2c3f72d55aefaa773c9a3137645b32
SHA1 hash: 9d554a321001513dc5365632b7cf31939d4efa9b
MD5 hash: d577e00d83444556f14015d368e6815c
humanhash: floor-delta-lithium-solar
File name:4fbb1ebdae240e9a784ff893b113fe3244945ab322b4e733baa13a1a309ee4bf
Download: download sample
File size:2'060'288 bytes
First seen:2026-07-22 11:00:18 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 49152:ks3VLh6Yg8mAug8Hzi3HPWHvCyQME/ewgm1pmvcxOqhVN1oTHDdor:p3j1g8918IWPVQMWEOiOOKSTHDdor
TLSH T17095330C02DAF36AAADE7F80CDC9B8F41CC626F551857DD29A1DB4758F3A4A720E5D80
Magika gzip
Reporter EnthecSolutions
Tags:enthec gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
CA CA
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:4fbb1ebdae240e9a784ff893b113fe3244945ab322b4e733baa13a1a309ee4bf~
File size:2'158'613 bytes
SHA256 hash: 879434af60b564d2be361fff9a8c6298195a2c3e8fa4794a040268dcc2f2d75e
MD5 hash: 76ddfa679c7bca13d8d18764d1d89066
MIME type:application/x-tar
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
gz
First seen:
2026-07-22T10:18:00Z UTC
Last seen:
2026-07-22T10:33:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
GZip Archive
Threat name:
Linux.Dropper.ShellAgent
Status:
Malicious
First seen:
2026-07-22 11:14:55 UTC
AV detection:
20 of 38 (52.63%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence rootkit upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Enumerates running processes
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Loads a kernel module
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments