🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6497f4d0c65e56b12ea4dfd170bfac891cf8b4612fa4e8fa4825cb59a8b96ea8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6497f4d0c65e56b12ea4dfd170bfac891cf8b4612fa4e8fa4825cb59a8b96ea8
SHA3-384 hash: a8b87f45bf41efc8290f040e934ae23100a3077c97f89ecd15e70113a382ef4df095689d16bfb420de15c36401c8424b
SHA1 hash: c3a2beda3998b6e0ce1fcae63f7f25c4fe12e39b
MD5 hash: 224443c8b8cfca5467c5fcc94f913025
humanhash: oscar-jupiter-oscar-cola
File name:302l
Download: download sample
File size:293 bytes
First seen:2026-09-30 18:11:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:UqLqhR47DcKULt1cK8MNIiAz+MNIcK8MNQkYcK8MN25FTEX3:UquhRADEt1VAgVIVsQ
TLSH T147E08C50E6A13E142675E90A83D4930A927557B0B94CBA6D94D986E20AA44C2358DF94
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter arados
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://84.200.33.163/302/tokenlinux.shn/an/a DPRK git-hook js NodeJS sh XCTDH ContagiousInterview

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
HR HR
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
bash lolbin
Status:
terminated
Behavior Graph:
%3 guuid=b92bd2ea-1b00-0000-694f-656dce090000 pid=2510 /usr/bin/sudo guuid=8c5364ee-1b00-0000-694f-656dd7090000 pid=2519 /tmp/sample.bin guuid=b92bd2ea-1b00-0000-694f-656dce090000 pid=2510->guuid=8c5364ee-1b00-0000-694f-656dd7090000 pid=2519 execve guuid=abf31aef-1b00-0000-694f-656dda090000 pid=2522 /usr/bin/mkdir guuid=8c5364ee-1b00-0000-694f-656dd7090000 pid=2519->guuid=abf31aef-1b00-0000-694f-656dda090000 pid=2522 execve guuid=f58fbfef-1b00-0000-694f-656ddc090000 pid=2524 /usr/bin/clear guuid=8c5364ee-1b00-0000-694f-656dd7090000 pid=2519->guuid=f58fbfef-1b00-0000-694f-656ddc090000 pid=2524 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6497f4d0c65e56b12ea4dfd170bfac891cf8b4612fa4e8fa4825cb59a8b96ea8

(this sample)

  
Delivery method
Distributed via web download

Comments