🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 57b590d336b79a0df8be3712bc9f205a8d41a87620d4bc6fc1df2a4a8cf3a9c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 57b590d336b79a0df8be3712bc9f205a8d41a87620d4bc6fc1df2a4a8cf3a9c9
SHA3-384 hash: 1595649a7a4a5618bf7c2d2b36b700756c81d41a0c2cfead4c317857aca04941bc71dd8de12699bfa447921936bfa164
SHA1 hash: d6532664e8ab74d7adc5b3a83d7e01c83b46c65f
MD5 hash: 094425d49c87f8358546603e63468f05
humanhash: quiet-edward-double-idaho
File name:install.sh
Download: download sample
File size:7'519 bytes
First seen:2026-09-27 06:38:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:I5JjV4V/Ljqk79IV4w5FJT9agJXZZIURP7FQ61/jk//CEXxTK2l170as0gU8i8LW:iLe+T7aaIURzO617kCEXNlVgU8gf
TLSH T10FF19481B1E0DA72768DC87D278B1085B68F051B092D3C28B4DE79243F399B5F0FA766
TrID 70.0% (.) Unix-like shebang (var.1) (gen) (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-27T03:55:00Z UTC
Last seen:
2026-09-29T00:10:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=4de0f0d6-1800-0000-b8ba-0e34360d0000 pid=3382 /usr/bin/sudo guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385 /usr/bin/bash guuid=4de0f0d6-1800-0000-b8ba-0e34360d0000 pid=3382->guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385 execve guuid=667a52da-1800-0000-b8ba-0e343a0d0000 pid=3386 /usr/bin/bash guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=667a52da-1800-0000-b8ba-0e343a0d0000 pid=3386 clone guuid=4a9a21db-1800-0000-b8ba-0e343f0d0000 pid=3391 /usr/bin/bash guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=4a9a21db-1800-0000-b8ba-0e343f0d0000 pid=3391 clone guuid=e9dc2cdc-1800-0000-b8ba-0e34470d0000 pid=3399 /usr/bin/curl net send-data guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=e9dc2cdc-1800-0000-b8ba-0e34470d0000 pid=3399 execve guuid=adbed5e5-1800-0000-b8ba-0e34530d0000 pid=3411 /usr/bin/rm guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=adbed5e5-1800-0000-b8ba-0e34530d0000 pid=3411 execve guuid=a3d33de6-1800-0000-b8ba-0e34550d0000 pid=3413 /usr/bin/curl net send-data write-file guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=a3d33de6-1800-0000-b8ba-0e34550d0000 pid=3413 execve guuid=43784bf1-1800-0000-b8ba-0e34630d0000 pid=3427 /usr/bin/mv guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=43784bf1-1800-0000-b8ba-0e34630d0000 pid=3427 execve guuid=2a6aadf1-1800-0000-b8ba-0e34650d0000 pid=3429 /usr/bin/chmod guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=2a6aadf1-1800-0000-b8ba-0e34650d0000 pid=3429 execve guuid=9cecf4f1-1800-0000-b8ba-0e34670d0000 pid=3431 /tmp/bot guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=9cecf4f1-1800-0000-b8ba-0e34670d0000 pid=3431 execve guuid=6f66fef1-1800-0000-b8ba-0e34680d0000 pid=3432 /usr/bin/sleep guuid=5f460bd9-1800-0000-b8ba-0e34390d0000 pid=3385->guuid=6f66fef1-1800-0000-b8ba-0e34680d0000 pid=3432 execve guuid=b9b269da-1800-0000-b8ba-0e343b0d0000 pid=3387 /usr/bin/touch guuid=667a52da-1800-0000-b8ba-0e343a0d0000 pid=3386->guuid=b9b269da-1800-0000-b8ba-0e343b0d0000 pid=3387 execve guuid=492fceda-1800-0000-b8ba-0e343d0d0000 pid=3389 /usr/bin/rm delete-file guuid=667a52da-1800-0000-b8ba-0e343a0d0000 pid=3386->guuid=492fceda-1800-0000-b8ba-0e343d0d0000 pid=3389 execve guuid=041f35db-1800-0000-b8ba-0e34400d0000 pid=3392 /usr/bin/bash guuid=4a9a21db-1800-0000-b8ba-0e343f0d0000 pid=3391->guuid=041f35db-1800-0000-b8ba-0e34400d0000 pid=3392 clone guuid=4d4e99db-1800-0000-b8ba-0e34440d0000 pid=3396 /usr/bin/bash guuid=4a9a21db-1800-0000-b8ba-0e343f0d0000 pid=3391->guuid=4d4e99db-1800-0000-b8ba-0e34440d0000 pid=3396 clone guuid=c22c45db-1800-0000-b8ba-0e34410d0000 pid=3393 /usr/bin/uname guuid=041f35db-1800-0000-b8ba-0e34400d0000 pid=3392->guuid=c22c45db-1800-0000-b8ba-0e34410d0000 pid=3393 execve guuid=910baadb-1800-0000-b8ba-0e34450d0000 pid=3397 /usr/bin/getconf guuid=4d4e99db-1800-0000-b8ba-0e34440d0000 pid=3396->guuid=910baadb-1800-0000-b8ba-0e34450d0000 pid=3397 execve c6d461f8-86d7-5a5b-8253-1f601f5faade 217.60.195.161:80 guuid=e9dc2cdc-1800-0000-b8ba-0e34470d0000 pid=3399->c6d461f8-86d7-5a5b-8253-1f601f5faade send: 82B guuid=a3d33de6-1800-0000-b8ba-0e34550d0000 pid=3413->c6d461f8-86d7-5a5b-8253-1f601f5faade send: 81B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-27 06:38:56 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments