MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e80ea9b0381f09aab4d1a4c176cc98b15fab32efeb9fc345862fa6182d5a17a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5e80ea9b0381f09aab4d1a4c176cc98b15fab32efeb9fc345862fa6182d5a17a
SHA3-384 hash: 061d6dc5b69698e7000cc133fa5aff910a0faacfe6d7ff070162b12a17d95027cd59c85e3af2e0f0bcaa4bf8173839df
SHA1 hash: d18cd19933ed513dfa28b24d1be24a5ce465d53c
MD5 hash: ba2c7d61f71dc160a35c9a8c40905b99
humanhash: five-michigan-yellow-crazy
File name:l
Download: download sample
File size:811 bytes
First seen:2026-05-14 19:29:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KVmHXEfNeErm79WbzpDyqRGpNPlnSwbJ64NpOQ7jQjOGK/op9QhrULhMQ0:KVAXElDpbzZNGjPlnBTpFd/op9Q9ST0
TLSH T1B801BDEBB8338871BBCD0439636A75540D86863B8DA1DE44358EA8042FD8758B45F390
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
0
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-13T04:56:00Z UTC
Last seen:
2026-05-14T18:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=6bd619e0-1800-0000-2e09-f937a9050000 pid=1449 /usr/bin/sudo guuid=c2e1a4e1-1800-0000-2e09-f937b0050000 pid=1456 /tmp/sample.bin guuid=6bd619e0-1800-0000-2e09-f937a9050000 pid=1449->guuid=c2e1a4e1-1800-0000-2e09-f937b0050000 pid=1456 execve guuid=279ed7e1-1800-0000-2e09-f937b1050000 pid=1457 /usr/bin/busybox guuid=c2e1a4e1-1800-0000-2e09-f937b0050000 pid=1456->guuid=279ed7e1-1800-0000-2e09-f937b1050000 pid=1457 execve guuid=ac5c09e2-1800-0000-2e09-f937b3050000 pid=1459 /usr/bin/wget guuid=c2e1a4e1-1800-0000-2e09-f937b0050000 pid=1456->guuid=ac5c09e2-1800-0000-2e09-f937b3050000 pid=1459 execve
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments