MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55555e947e261ba604d11975dced1e7db63adf6e1f36b65aec5bb0de45cc7ed7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 55555e947e261ba604d11975dced1e7db63adf6e1f36b65aec5bb0de45cc7ed7
SHA3-384 hash: 39e2c46ad31f78a713b5d0c209a3945e3c1803f2426c5eb3c88aa655b1a8cdb9e7044ac8d1d0565d5cd795b4a35d9b97
SHA1 hash: 6189cf4804ed47fa650d2f8f8514bc5c4dfa6aca
MD5 hash: 0930be6385735022876dc185dfc10531
humanhash: dakota-venus-wisconsin-wolfram
File name:mac
Download: download sample
File size:1'113 bytes
First seen:2026-08-07 15:44:18 UTC
Last seen:2026-08-08 09:47:31 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:UGxVEb81iVnONd/4Lrykec0yVdykUkqWTOVju+kqVqQWsDL:UGwCUvHykvykUkqoL+kRD0L
TLSH T1DB21CB193E8374A44333D06A34EE30D2CB885270EB9479743C261B949801ACA2C7EA97
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://quick-load.vercel.app/api/settings/bootstraplinuxn/an/aua-curl

Intelligence


File Origin
# of uploads :
3
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
bash lolbin
Status:
terminated
Behavior Graph:
%3 guuid=4ad671ef-1600-0000-bbbf-798c520d0000 pid=3410 /usr/bin/sudo guuid=8ac5fff0-1600-0000-bbbf-798c580d0000 pid=3416 /tmp/sample.bin guuid=4ad671ef-1600-0000-bbbf-798c520d0000 pid=3410->guuid=8ac5fff0-1600-0000-bbbf-798c580d0000 pid=3416 execve guuid=efab64f1-1600-0000-bbbf-798c5a0d0000 pid=3418 /usr/bin/mkdir guuid=8ac5fff0-1600-0000-bbbf-798c580d0000 pid=3416->guuid=efab64f1-1600-0000-bbbf-798c5a0d0000 pid=3418 execve guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3420 /usr/bin/curl net send-data write-file guuid=8ac5fff0-1600-0000-bbbf-798c580d0000 pid=3416->guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3420 execve guuid=332c830e-1700-0000-bbbf-798caa0d0000 pid=3498 /usr/bin/chmod guuid=8ac5fff0-1600-0000-bbbf-798c580d0000 pid=3416->guuid=332c830e-1700-0000-bbbf-798caa0d0000 pid=3498 execve guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499 /usr/bin/bash guuid=8ac5fff0-1600-0000-bbbf-798c580d0000 pid=3416->guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499 execve c64ad788-4de8-592d-acbb-043526c6844e quick-load.vercel.app:443 guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3420->c64ad788-4de8-592d-acbb-043526c6844e send: 786B guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3435 /usr/bin/curl dns net send-data guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3420->guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3435 clone guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3435->c64ad788-4de8-592d-acbb-043526c6844e con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=350e04f2-1600-0000-bbbf-798c5c0d0000 pid=3435->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 78B guuid=b1573710-1700-0000-bbbf-798caf0d0000 pid=3503 /usr/bin/uname guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=b1573710-1700-0000-bbbf-798caf0d0000 pid=3503 execve guuid=8968b510-1700-0000-bbbf-798cb30d0000 pid=3507 /usr/bin/bash guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=8968b510-1700-0000-bbbf-798cb30d0000 pid=3507 clone guuid=306a1e11-1700-0000-bbbf-798cb70d0000 pid=3511 /usr/bin/basename guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=306a1e11-1700-0000-bbbf-798cb70d0000 pid=3511 execve guuid=3a17ba11-1700-0000-bbbf-798cbb0d0000 pid=3515 /usr/bin/bash guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=3a17ba11-1700-0000-bbbf-798cbb0d0000 pid=3515 clone guuid=e2d20926-1700-0000-bbbf-798ce30d0000 pid=3555 /usr/bin/bash guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=e2d20926-1700-0000-bbbf-798ce30d0000 pid=3555 clone guuid=4f2a2f26-1700-0000-bbbf-798ce40d0000 pid=3556 /usr/bin/mkdir guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=4f2a2f26-1700-0000-bbbf-798ce40d0000 pid=3556 execve guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3557 /usr/bin/curl net send-data write-file guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3557 execve guuid=2fded9db-1700-0000-bbbf-798cef0f0000 pid=4079 /usr/bin/tar delete-file write-file guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=2fded9db-1700-0000-bbbf-798cef0f0000 pid=4079 execve guuid=2e9226ba-1c00-0000-bbbf-798c1d140000 pid=5149 /usr/bin/rm delete-file guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=2e9226ba-1c00-0000-bbbf-798c1d140000 pid=5149 execve guuid=5afde5ba-1c00-0000-bbbf-798c1e140000 pid=5150 /root/.vscode/node-v26.7.0-linux-x64/bin/node guuid=7ee0ff0e-1700-0000-bbbf-798cab0d0000 pid=3499->guuid=5afde5ba-1c00-0000-bbbf-798c1e140000 pid=5150 execve guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3516 /usr/bin/curl net send-data guuid=3a17ba11-1700-0000-bbbf-798cbb0d0000 pid=3515->guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3516 execve guuid=cebd1e12-1700-0000-bbbf-798cbd0d0000 pid=3517 /usr/bin/grep guuid=3a17ba11-1700-0000-bbbf-798cbb0d0000 pid=3515->guuid=cebd1e12-1700-0000-bbbf-798cbd0d0000 pid=3517 execve guuid=76473212-1700-0000-bbbf-798cbf0d0000 pid=3519 /usr/bin/head guuid=3a17ba11-1700-0000-bbbf-798cbb0d0000 pid=3515->guuid=76473212-1700-0000-bbbf-798cbf0d0000 pid=3519 execve guuid=fad15312-1700-0000-bbbf-798cc00d0000 pid=3520 /usr/bin/cut guuid=3a17ba11-1700-0000-bbbf-798cbb0d0000 pid=3515->guuid=fad15312-1700-0000-bbbf-798cc00d0000 pid=3520 execve 81b97d64-96dc-5e75-a02c-ce4c884ef31c nodejs.org:443 guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3516->81b97d64-96dc-5e75-a02c-ce4c884ef31c send: 786B guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3528 /usr/bin/curl dns net send-data guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3516->guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3528 clone guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3528->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B guuid=a35df711-1700-0000-bbbf-798cbc0d0000 pid=3528->81b97d64-96dc-5e75-a02c-ce4c884ef31c con guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3557->81b97d64-96dc-5e75-a02c-ce4c884ef31c send: 854B guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3566 /usr/bin/curl dns net send-data guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3557->guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3566 clone guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3566->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B guuid=347d8c26-1700-0000-bbbf-798ce50d0000 pid=3566->81b97d64-96dc-5e75-a02c-ce4c884ef31c con guuid=3a1e48dc-1700-0000-bbbf-798cf30f0000 pid=4083 /usr/bin/xz guuid=2fded9db-1700-0000-bbbf-798cef0f0000 pid=4079->guuid=3a1e48dc-1700-0000-bbbf-798cf30f0000 pid=4083 execve
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux
Behaviour
Command and Scripting Interpreter: JavaScript
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 55555e947e261ba604d11975dced1e7db63adf6e1f36b65aec5bb0de45cc7ed7

(this sample)

6effad9fdee81589b37c60bbbae20483200bf53bee3e3c107b1aa47d2ac4ccb3

  
Delivery method
Distributed via web download

Comments