MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53ad9731fa855c98d6f2befd2b31a52a28cb1eadb4d72424e56f3896f6516f63. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 53ad9731fa855c98d6f2befd2b31a52a28cb1eadb4d72424e56f3896f6516f63
SHA3-384 hash: 595bbee6def0997794d0e468cd60d36179d01070a3980628e7d0e5203ad89988d3ab888eac78a6a6ec007f7e7f9ede5b
SHA1 hash: fc3a449c095e60d3e612d5931ecfb77a7c14aa02
MD5 hash: 8c4e11e3063fd907e541d4a81547ac98
humanhash: twenty-west-diet-mobile
File name:av.sh
Download: download sample
File size:314 bytes
First seen:2025-09-03 04:14:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:6XtDVLf+gqXUvUSidHeKzSIO1aiiEDVacRgqXUvUSidHBEzFaDSINXsFE3iBqVtT:aSF5e1jakF5yzFbE0E3cRF5Ma0LKif
TLSH T18BE0B6C4F42236F35FCE6C4FB372881A1866E14C4496A2D6EE5A906D9174F45F531305
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
ftp://9.177.197.168:8021/arm5n/an/an/a
ftp://9.177.197.168:8021/arm4n/an/an/a
ftp://9.177.197.168:8021/arm7n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
text
First seen:
2024-04-14T16:45:00Z UTC
Last seen:
2024-04-14T16:45:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=7e1e5fcb-1900-0000-d1db-0b5bc30a0000 pid=2755 /usr/bin/sudo guuid=e93c94cd-1900-0000-d1db-0b5bca0a0000 pid=2762 /tmp/sample.bin guuid=7e1e5fcb-1900-0000-d1db-0b5bc30a0000 pid=2755->guuid=e93c94cd-1900-0000-d1db-0b5bca0a0000 pid=2762 execve guuid=d8a7e4cd-1900-0000-d1db-0b5bcb0a0000 pid=2763 /usr/bin/rm guuid=e93c94cd-1900-0000-d1db-0b5bca0a0000 pid=2762->guuid=d8a7e4cd-1900-0000-d1db-0b5bcb0a0000 pid=2763 execve guuid=2c6f77ce-1900-0000-d1db-0b5bcd0a0000 pid=2765 /usr/bin/busybox guuid=e93c94cd-1900-0000-d1db-0b5bca0a0000 pid=2762->guuid=2c6f77ce-1900-0000-d1db-0b5bcd0a0000 pid=2765 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 53ad9731fa855c98d6f2befd2b31a52a28cb1eadb4d72424e56f3896f6516f63

(this sample)

  
Delivery method
Distributed via web download

Comments