MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 50ccd7cd274ea9f849c4d831f50aa0ffdcf4708594aee8b3c8fce377b384ea38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 50ccd7cd274ea9f849c4d831f50aa0ffdcf4708594aee8b3c8fce377b384ea38
SHA3-384 hash: 8d8f06ca534b1eefd7ea3849eaa25038b71887f64663b74f83b92a09bcf1d0511ad59c661371c6a8de650f38d3892005
SHA1 hash: 584dab77bfd184eca58c5eee26d3ca0518ff9196
MD5 hash: 5697d282e1d2571c903894624a5a6846
humanhash: sad-shade-romeo-finch
File name:shk
Download: download sample
File size:271 bytes
First seen:2025-09-21 13:51:45 UTC
Last seen:2025-09-22 05:48:46 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+E2VYs5CYf53I3h3FoF/f4MVKhOXqIKXD73IKX+N1IEWYq1IKBK0:ZtJ+E2EYi4FIMghsOTh4WYO80
TLSH T1FDD02B18FC51087374704CB9E7F73491E00F920A2E06948E7189521BEBA5A40F040153
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-21T12:41:00Z UTC
Last seen:
2025-09-21T12:41:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=db29e1af-1a00-0000-bb31-1b8ea10b0000 pid=2977 /usr/bin/sudo guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984 /tmp/sample.bin guuid=db29e1af-1a00-0000-bb31-1b8ea10b0000 pid=2977->guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984 execve guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=2985 /usr/bin/curl net send-data write-file guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=2985 execve guuid=054268d1-1a00-0000-bb31-1b8ef50b0000 pid=3061 /usr/bin/chmod guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=054268d1-1a00-0000-bb31-1b8ef50b0000 pid=3061 execve guuid=3588a5d1-1a00-0000-bb31-1b8ef70b0000 pid=3063 /usr/bin/dash guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=3588a5d1-1a00-0000-bb31-1b8ef70b0000 pid=3063 clone guuid=7cdaaed1-1a00-0000-bb31-1b8ef80b0000 pid=3064 /usr/bin/rm guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=7cdaaed1-1a00-0000-bb31-1b8ef80b0000 pid=3064 execve guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3066 /usr/bin/curl net send-data write-file guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3066 execve guuid=a6c6d4ec-1a00-0000-bb31-1b8e3e0c0000 pid=3134 /usr/bin/chmod guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=a6c6d4ec-1a00-0000-bb31-1b8e3e0c0000 pid=3134 execve guuid=d78daaed-1a00-0000-bb31-1b8e420c0000 pid=3138 /usr/bin/dash guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=d78daaed-1a00-0000-bb31-1b8e420c0000 pid=3138 clone guuid=65abb6ed-1a00-0000-bb31-1b8e430c0000 pid=3139 /usr/bin/rm guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=65abb6ed-1a00-0000-bb31-1b8e430c0000 pid=3139 execve guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3142 /usr/bin/curl net send-data write-file guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3142 execve guuid=824a5a0d-1b00-0000-bb31-1b8e720c0000 pid=3186 /usr/bin/chmod guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=824a5a0d-1b00-0000-bb31-1b8e720c0000 pid=3186 execve guuid=8687ab0d-1b00-0000-bb31-1b8e730c0000 pid=3187 /usr/bin/dash guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=8687ab0d-1b00-0000-bb31-1b8e730c0000 pid=3187 clone guuid=b249b90d-1b00-0000-bb31-1b8e740c0000 pid=3188 /usr/bin/rm guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=b249b90d-1b00-0000-bb31-1b8e740c0000 pid=3188 execve guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3189 /usr/bin/curl net send-data write-file guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3189 execve guuid=940c2026-1b00-0000-bb31-1b8e9b0c0000 pid=3227 /usr/bin/chmod guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=940c2026-1b00-0000-bb31-1b8e9b0c0000 pid=3227 execve guuid=1dbb8c26-1b00-0000-bb31-1b8e9c0c0000 pid=3228 /usr/bin/dash guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=1dbb8c26-1b00-0000-bb31-1b8e9c0c0000 pid=3228 clone guuid=b96d9426-1b00-0000-bb31-1b8e9d0c0000 pid=3229 /usr/bin/rm guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=b96d9426-1b00-0000-bb31-1b8e9d0c0000 pid=3229 execve guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3230 /usr/bin/curl net send-data write-file guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3230 execve guuid=dbd39240-1b00-0000-bb31-1b8eae0c0000 pid=3246 /usr/bin/chmod guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=dbd39240-1b00-0000-bb31-1b8eae0c0000 pid=3246 execve guuid=7829df40-1b00-0000-bb31-1b8eaf0c0000 pid=3247 /usr/bin/dash guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=7829df40-1b00-0000-bb31-1b8eaf0c0000 pid=3247 clone guuid=648eed40-1b00-0000-bb31-1b8eb00c0000 pid=3248 /usr/bin/rm guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=648eed40-1b00-0000-bb31-1b8eb00c0000 pid=3248 execve guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3249 /usr/bin/curl net send-data write-file guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3249 execve guuid=04154958-1b00-0000-bb31-1b8ecf0c0000 pid=3279 /usr/bin/chmod guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=04154958-1b00-0000-bb31-1b8ecf0c0000 pid=3279 execve guuid=0bf9c958-1b00-0000-bb31-1b8ed00c0000 pid=3280 /usr/bin/dash guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=0bf9c958-1b00-0000-bb31-1b8ed00c0000 pid=3280 clone guuid=5d00da58-1b00-0000-bb31-1b8ed10c0000 pid=3281 /usr/bin/rm guuid=125558b2-1a00-0000-bb31-1b8ea80b0000 pid=2984->guuid=5d00da58-1b00-0000-bb31-1b8ed10c0000 pid=3281 execve 9df19bce-d755-5940-91ff-d0e847757959 109.205.213.5:80 guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=2985->9df19bce-d755-5940-91ff-d0e847757959 send: 90B guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=3059 /usr/bin/curl dns net send-data guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=2985->guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=3059 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=72e3aab2-1a00-0000-bb31-1b8ea90b0000 pid=3059->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3066->9df19bce-d755-5940-91ff-d0e847757959 send: 90B guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3131 /usr/bin/curl dns net send-data guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3066->guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3131 clone guuid=530ffed1-1a00-0000-bb31-1b8efa0b0000 pid=3131->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3142->9df19bce-d755-5940-91ff-d0e847757959 send: 90B guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3185 /usr/bin/curl dns net send-data guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3142->guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3185 clone guuid=a73d14ee-1a00-0000-bb31-1b8e460c0000 pid=3185->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3189->9df19bce-d755-5940-91ff-d0e847757959 send: 90B guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3226 /usr/bin/curl dns net send-data guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3189->guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3226 clone guuid=0adf1c0e-1b00-0000-bb31-1b8e750c0000 pid=3226->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3230->9df19bce-d755-5940-91ff-d0e847757959 send: 90B guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3245 /usr/bin/curl dns net send-data guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3230->guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3245 clone guuid=950b2027-1b00-0000-bb31-1b8e9e0c0000 pid=3245->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3249->9df19bce-d755-5940-91ff-d0e847757959 send: 89B guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3278 /usr/bin/curl dns net send-data guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3249->guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3278 clone guuid=784a4e41-1b00-0000-bb31-1b8eb10c0000 pid=3278->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 92B
Threat name:
Win32.Trojan.MiraiB
Status:
Malicious
First seen:
2025-09-21 14:22:11 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 50ccd7cd274ea9f849c4d831f50aa0ffdcf4708594aee8b3c8fce377b384ea38

(this sample)

  
Delivery method
Distributed via web download

Comments