MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 517fb0cf651e8382c9081abd9f3a73019650b39f20929463f45e0ca9175379a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 517fb0cf651e8382c9081abd9f3a73019650b39f20929463f45e0ca9175379a9
SHA3-384 hash: 96076503f51bcd5862215b25699dca3cc979231c36091569db9284fbee08e16586e8579802ad1c8216acdf6a2c2e5a47
SHA1 hash: b44e54f4046edb08dbec1512f140561370beb6a0
MD5 hash: fcc543a0e9bf3db2931f1bb73b17bb07
humanhash: comet-pluto-pip-nine
File name:sleep.sh
Download: download sample
File size:586 bytes
First seen:2025-07-16 02:45:05 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:3f0XKNC1TmLtZoFbUKFz3KNC1TmLtZXsJYZ2FOy6vxzaKQrJPBfUJlIOy630T:8XKNC8RZo1UGz3KNC8RZXsA2FOJkKQrV
TLSH T1A0F02B9E216B7A21404B811453EF83986B00415F97588E397CBCB234FA9CE4060FEFC7
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://151.106.34.115:6573/mon.shn/an/ash

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=0668f8b5-1a00-0000-a8aa-78158a0b0000 pid=2954 /usr/bin/sudo guuid=b5e348b8-1a00-0000-a8aa-78158f0b0000 pid=2959 /tmp/sample.bin guuid=0668f8b5-1a00-0000-a8aa-78158a0b0000 pid=2954->guuid=b5e348b8-1a00-0000-a8aa-78158f0b0000 pid=2959 execve guuid=1399ceb8-1a00-0000-a8aa-7815910b0000 pid=2961 /usr/bin/wget guuid=b5e348b8-1a00-0000-a8aa-78158f0b0000 pid=2959->guuid=1399ceb8-1a00-0000-a8aa-7815910b0000 pid=2961 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-01-11 07:02:04 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
linux
Behaviour
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 517fb0cf651e8382c9081abd9f3a73019650b39f20929463f45e0ca9175379a9

(this sample)

  
Delivery method
Distributed via web download

Comments