🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e48566ea6c0831641fc974970151b457e6e57d3fdc7c134c656d00551b8eb88. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5e48566ea6c0831641fc974970151b457e6e57d3fdc7c134c656d00551b8eb88
SHA3-384 hash: 846555901f008fb881cc2a8fbc6de456da874c5fb0e87aea0bd8916a26b705008118fa8174a70bcdef596c171c64f920
SHA1 hash: aa61c90dbca7f7fabae7fe010bdfc7a9d43cc666
MD5 hash: f38b49295d1377c349892409bd1e67b1
humanhash: texas-hamper-hawaii-south
File name:w3.sh
Download: download sample
File size:335 bytes
First seen:2026-08-31 17:40:46 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:+Ycy+JF+OuyzvCCpFpoavxbYh+4k/GCabY20su6MMJN:+Cm+OuyLCEUavxMh+4k/uMKJ
TLSH T1B9E07D60FF5092F823D043B95949F58139171FF30F9438B9F14E256530A084E383A8AA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
AT AT
Vendor Threat Intelligence
No detections
Verdict:
Unknown
File Type:
unix shell
First seen:
2026-08-31T15:29:00Z UTC
Last seen:
2026-08-31T15:50:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e5d50b32-1a00-0000-a7c7-9d8f580a0000 pid=2648 /usr/bin/sudo guuid=e990c433-1a00-0000-a7c7-9d8f5f0a0000 pid=2655 /tmp/sample.bin guuid=e5d50b32-1a00-0000-a7c7-9d8f580a0000 pid=2648->guuid=e990c433-1a00-0000-a7c7-9d8f5f0a0000 pid=2655 execve guuid=395f4d34-1a00-0000-a7c7-9d8f610a0000 pid=2657 /usr/bin/ps guuid=e990c433-1a00-0000-a7c7-9d8f5f0a0000 pid=2655->guuid=395f4d34-1a00-0000-a7c7-9d8f610a0000 pid=2657 execve guuid=6c39f53c-1a00-0000-a7c7-9d8f6b0a0000 pid=2667 /usr/bin/bash guuid=e990c433-1a00-0000-a7c7-9d8f5f0a0000 pid=2655->guuid=6c39f53c-1a00-0000-a7c7-9d8f6b0a0000 pid=2667 clone guuid=5bf17c3d-1a00-0000-a7c7-9d8f700a0000 pid=2672 /usr/bin/bash guuid=e990c433-1a00-0000-a7c7-9d8f5f0a0000 pid=2655->guuid=5bf17c3d-1a00-0000-a7c7-9d8f700a0000 pid=2672 clone guuid=9853073d-1a00-0000-a7c7-9d8f6c0a0000 pid=2668 /usr/bin/bash guuid=6c39f53c-1a00-0000-a7c7-9d8f6b0a0000 pid=2667->guuid=9853073d-1a00-0000-a7c7-9d8f6c0a0000 pid=2668 clone guuid=d3da0f3d-1a00-0000-a7c7-9d8f6d0a0000 pid=2669 /usr/bin/mawk guuid=6c39f53c-1a00-0000-a7c7-9d8f6b0a0000 pid=2667->guuid=d3da0f3d-1a00-0000-a7c7-9d8f6d0a0000 pid=2669 execve
Threat name:
Script-BAT.PUA.Miner
Status:
Malicious
First seen:
2026-07-15 15:49:18 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Reads CPU attributes
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5e48566ea6c0831641fc974970151b457e6e57d3fdc7c134c656d00551b8eb88

(this sample)

  
Delivery method
Distributed via web download

Comments