MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 530d9ed2b62d1bfc5fdb39938e26d059cddfb65e0f7ae6df4ab971a15829e63c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 530d9ed2b62d1bfc5fdb39938e26d059cddfb65e0f7ae6df4ab971a15829e63c
SHA3-384 hash: d8a2f2efcec4f525355a9c786da64876c5ca6dd19069f0051e8a27ec0d230b9d615157e02149510ff89e18dd59206cd0
SHA1 hash: 9e73761636b6d2a6ef2d194aa11956f776da052b
MD5 hash: ff5bbde389b7b7fc1502a65c992c2f5c
humanhash: jupiter-avocado-queen-mexico
File name:kamru.sh
Download: download sample
File size:1'138 bytes
First seen:2026-05-01 14:55:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:v1Svl4erIKk3yIFydWs+X3gv7ZTPpaWFZMu8OydO:tS9hIGWNngDZThRHMVOCO
TLSH T1192187D3161045312BA58E0EE0D57688E27A7D63D283FD3438DF6A105BEF86BE209276
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-01T11:33:00Z UTC
Last seen:
2026-05-01T11:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=fc18848e-1600-0000-ec62-5602aa0c0000 pid=3242 /usr/bin/sudo guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243 /tmp/sample.bin guuid=fc18848e-1600-0000-ec62-5602aa0c0000 pid=3242->guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243 execve guuid=ca453b91-1600-0000-ec62-5602ac0c0000 pid=3244 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=ca453b91-1600-0000-ec62-5602ac0c0000 pid=3244 execve guuid=65421e97-1600-0000-ec62-5602bc0c0000 pid=3260 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=65421e97-1600-0000-ec62-5602bc0c0000 pid=3260 execve guuid=d0f66597-1600-0000-ec62-5602be0c0000 pid=3262 /tmp/k.x86 guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=d0f66597-1600-0000-ec62-5602be0c0000 pid=3262 execve guuid=01647497-1600-0000-ec62-5602bf0c0000 pid=3263 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=01647497-1600-0000-ec62-5602bf0c0000 pid=3263 execve guuid=df3ec2d3-1600-0000-ec62-5602320d0000 pid=3378 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=df3ec2d3-1600-0000-ec62-5602320d0000 pid=3378 execve guuid=a5054ad7-1600-0000-ec62-5602380d0000 pid=3384 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=a5054ad7-1600-0000-ec62-5602380d0000 pid=3384 execve guuid=eddae9d7-1600-0000-ec62-5602390d0000 pid=3385 /usr/bin/bash guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=eddae9d7-1600-0000-ec62-5602390d0000 pid=3385 clone guuid=95b2fcd7-1600-0000-ec62-56023a0d0000 pid=3386 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=95b2fcd7-1600-0000-ec62-56023a0d0000 pid=3386 execve guuid=87581214-1700-0000-ec62-5602d20d0000 pid=3538 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=87581214-1700-0000-ec62-5602d20d0000 pid=3538 execve guuid=40293517-1700-0000-ec62-5602db0d0000 pid=3547 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=40293517-1700-0000-ec62-5602db0d0000 pid=3547 execve guuid=dad38f17-1700-0000-ec62-5602dd0d0000 pid=3549 /usr/bin/bash guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=dad38f17-1700-0000-ec62-5602dd0d0000 pid=3549 clone guuid=9dd89a17-1700-0000-ec62-5602de0d0000 pid=3550 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=9dd89a17-1700-0000-ec62-5602de0d0000 pid=3550 execve guuid=61f59553-1700-0000-ec62-5602db0e0000 pid=3803 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=61f59553-1700-0000-ec62-5602db0e0000 pid=3803 execve guuid=e1be4a56-1700-0000-ec62-5602ed0e0000 pid=3821 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=e1be4a56-1700-0000-ec62-5602ed0e0000 pid=3821 execve guuid=a14c8756-1700-0000-ec62-5602f00e0000 pid=3824 /usr/bin/bash guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=a14c8756-1700-0000-ec62-5602f00e0000 pid=3824 clone guuid=c03c9356-1700-0000-ec62-5602f10e0000 pid=3825 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=c03c9356-1700-0000-ec62-5602f10e0000 pid=3825 execve guuid=d5458092-1700-0000-ec62-5602d10f0000 pid=4049 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=d5458092-1700-0000-ec62-5602d10f0000 pid=4049 execve guuid=020d6a9c-1700-0000-ec62-5602f10f0000 pid=4081 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=020d6a9c-1700-0000-ec62-5602f10f0000 pid=4081 execve guuid=377ea69c-1700-0000-ec62-5602f30f0000 pid=4083 /tmp/k.arm7 guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=377ea69c-1700-0000-ec62-5602f30f0000 pid=4083 execve guuid=d44cad9c-1700-0000-ec62-5602f40f0000 pid=4084 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=d44cad9c-1700-0000-ec62-5602f40f0000 pid=4084 execve guuid=47768ed8-1700-0000-ec62-5602d1100000 pid=4305 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=47768ed8-1700-0000-ec62-5602d1100000 pid=4305 execve guuid=dfdc5ede-1700-0000-ec62-5602db100000 pid=4315 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=dfdc5ede-1700-0000-ec62-5602db100000 pid=4315 execve guuid=28f8b7de-1700-0000-ec62-5602dc100000 pid=4316 /usr/bin/bash guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=28f8b7de-1700-0000-ec62-5602dc100000 pid=4316 clone guuid=f20ccede-1700-0000-ec62-5602dd100000 pid=4317 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=f20ccede-1700-0000-ec62-5602dd100000 pid=4317 execve guuid=3360df1a-1800-0000-ec62-560282110000 pid=4482 /usr/bin/wget net send-data write-file guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=3360df1a-1800-0000-ec62-560282110000 pid=4482 execve guuid=bd462225-1800-0000-ec62-56029b110000 pid=4507 /usr/bin/chmod guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=bd462225-1800-0000-ec62-56029b110000 pid=4507 execve guuid=ba636925-1800-0000-ec62-56029d110000 pid=4509 /tmp/k.x86_64 guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=ba636925-1800-0000-ec62-56029d110000 pid=4509 execve guuid=2cf17225-1800-0000-ec62-56029e110000 pid=4510 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=2cf17225-1800-0000-ec62-56029e110000 pid=4510 execve guuid=e2366361-1800-0000-ec62-56023a120000 pid=4666 /usr/bin/sleep guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=e2366361-1800-0000-ec62-56023a120000 pid=4666 execve guuid=3868078c-1900-0000-ec62-560282140000 pid=5250 /usr/bin/rm guuid=b9efb990-1600-0000-ec62-5602ab0c0000 pid=3243->guuid=3868078c-1900-0000-ec62-560282140000 pid=5250 execve 72a78419-8065-5ec7-93ba-cdb426fb221b 176.65.139.161:80 guuid=ca453b91-1600-0000-ec62-5602ac0c0000 pid=3244->72a78419-8065-5ec7-93ba-cdb426fb221b send: 143B guuid=e9e3a897-1600-0000-ec62-5602c10c0000 pid=3265 /tmp/k.x86 net send-data zombie guuid=d0f66597-1600-0000-ec62-5602be0c0000 pid=3262->guuid=e9e3a897-1600-0000-ec62-5602c10c0000 pid=3265 clone d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 176.65.139.161:25596 guuid=e9e3a897-1600-0000-ec62-5602c10c0000 pid=3265->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 send: 10B guuid=df3ec2d3-1600-0000-ec62-5602320d0000 pid=3378->72a78419-8065-5ec7-93ba-cdb426fb221b send: 144B guuid=87581214-1700-0000-ec62-5602d20d0000 pid=3538->72a78419-8065-5ec7-93ba-cdb426fb221b send: 146B guuid=61f59553-1700-0000-ec62-5602db0e0000 pid=3803->72a78419-8065-5ec7-93ba-cdb426fb221b send: 143B guuid=d5458092-1700-0000-ec62-5602d10f0000 pid=4049->72a78419-8065-5ec7-93ba-cdb426fb221b send: 144B guuid=a5bfc69c-1700-0000-ec62-5602f50f0000 pid=4085 /tmp/k.arm7 net send-data zombie guuid=377ea69c-1700-0000-ec62-5602f30f0000 pid=4083->guuid=a5bfc69c-1700-0000-ec62-5602f50f0000 pid=4085 clone guuid=a5bfc69c-1700-0000-ec62-5602f50f0000 pid=4085->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 send: 10B guuid=47768ed8-1700-0000-ec62-5602d1100000 pid=4305->72a78419-8065-5ec7-93ba-cdb426fb221b send: 143B guuid=3360df1a-1800-0000-ec62-560282110000 pid=4482->72a78419-8065-5ec7-93ba-cdb426fb221b send: 146B guuid=79849725-1800-0000-ec62-5602a0110000 pid=4512 /tmp/k.x86_64 net send-data zombie guuid=ba636925-1800-0000-ec62-56029d110000 pid=4509->guuid=79849725-1800-0000-ec62-5602a0110000 pid=4512 clone guuid=79849725-1800-0000-ec62-5602a0110000 pid=4512->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 send: 10B
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-05-01 14:56:53 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 530d9ed2b62d1bfc5fdb39938e26d059cddfb65e0f7ae6df4ab971a15829e63c

(this sample)

  
Delivery method
Distributed via web download

Comments