MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52f39d0c0d008faf84dbd944cd37d20db616ffe1b2202222129d94951074625a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 52f39d0c0d008faf84dbd944cd37d20db616ffe1b2202222129d94951074625a
SHA3-384 hash: b84691ed6ac870b66d8fef9e6788e364a76c433343b6c97deb79e3302f8bd8f6cc52971f90bdc2c04ce78fd964fbf545
SHA1 hash: ee64199da59495d87afb27d166f801592548becc
MD5 hash: b8a45eda305456a2ffe44e29369975e3
humanhash: butter-uniform-connecticut-spring
File name:rev.sh
Download: download sample
File size:1'185 bytes
First seen:2026-07-13 06:10:07 UTC
Last seen:2026-07-13 20:55:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:w1NLde/C7Ur+SrNvNSL5lOKvH0TGz5lOKvH0TGP:wTZhU6SuOKvH0TGGKvH0TGP
TLSH T15D21ACB2F1F569753F748499A106D13036DA3B429BCC6CE289BC9EE23623559E090F11
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
6
# of downloads :
89
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash evasive lolbin
Status:
terminated
Behavior Graph:
%3 guuid=1f091d53-1900-0000-c50b-81e9a50e0000 pid=3749 /usr/bin/sudo guuid=23efd154-1900-0000-c50b-81e9ae0e0000 pid=3758 /tmp/sample.bin guuid=1f091d53-1900-0000-c50b-81e9a50e0000 pid=3749->guuid=23efd154-1900-0000-c50b-81e9ae0e0000 pid=3758 execve guuid=aae3bb55-1900-0000-c50b-81e9af0e0000 pid=3759 /usr/bin/bash net guuid=23efd154-1900-0000-c50b-81e9ae0e0000 pid=3758->guuid=aae3bb55-1900-0000-c50b-81e9af0e0000 pid=3759 clone guuid=b6e4215b-1900-0000-c50b-81e9bf0e0000 pid=3775 /usr/bin/bash net guuid=23efd154-1900-0000-c50b-81e9ae0e0000 pid=3758->guuid=b6e4215b-1900-0000-c50b-81e9bf0e0000 pid=3775 clone guuid=6e267860-1900-0000-c50b-81e9d70e0000 pid=3799 /usr/bin/perl net guuid=23efd154-1900-0000-c50b-81e9ae0e0000 pid=3758->guuid=6e267860-1900-0000-c50b-81e9d70e0000 pid=3799 execve guuid=274d976b-1900-0000-c50b-81e9ff0e0000 pid=3839 /usr/bin/python3.11 net guuid=23efd154-1900-0000-c50b-81e9ae0e0000 pid=3758->guuid=274d976b-1900-0000-c50b-81e9ff0e0000 pid=3839 execve 701f252f-6075-56ab-a10b-2159df003a3d 198.199.86.134:5656 guuid=aae3bb55-1900-0000-c50b-81e9af0e0000 pid=3759->701f252f-6075-56ab-a10b-2159df003a3d con guuid=b6e4215b-1900-0000-c50b-81e9bf0e0000 pid=3775->701f252f-6075-56ab-a10b-2159df003a3d con guuid=6e267860-1900-0000-c50b-81e9d70e0000 pid=3799->701f252f-6075-56ab-a10b-2159df003a3d con guuid=274d976b-1900-0000-c50b-81e9ff0e0000 pid=3839->701f252f-6075-56ab-a10b-2159df003a3d con
Threat name:
Script-Python.Trojan.ReverseShell
Status:
Malicious
First seen:
2026-07-13 06:11:04 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_shellpop_Bash
Author:Tobias Michalski
Description:Detects susupicious bash command
Reference:https://github.com/0x00-0x00/ShellPop

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 52f39d0c0d008faf84dbd944cd37d20db616ffe1b2202222129d94951074625a

(this sample)

  
Delivery method
Distributed via web download

Comments