MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 673337ea6fb0eba12c2e7abe1447878e7f9ee63dad296aa8ed47578bb0c1f039. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 673337ea6fb0eba12c2e7abe1447878e7f9ee63dad296aa8ed47578bb0c1f039
SHA3-384 hash: 6f561f9cf05c699e67f6d27430fc5fe97581b982d5a1aeb501aff7ef3d66091429b324cba71f34324d5abfa99a282fe4
SHA1 hash: 975a57af4de7634a6fa149b651603865b356e97d
MD5 hash: ac8c364e24688a56497b491c4d7a1f95
humanhash: burger-nineteen-london-solar
File name:curl.sh
Download: download sample
File size:1'414 bytes
First seen:2026-06-20 19:54:58 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:VB59HBqg5vFByqBC1IBdBnBdTcqBVBNB4bGBvf3ByClBNBMW3BpuBW:rThzd7jC18DBdo6rTNxyCT3x8g
TLSH T1F5213AC812A067F38BD8D940B96399EDB06D04D77E1798E4A4084AE36E563C6FC1C366
Magika txt
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=139271f8-1900-0000-de0e-67da480c0000 pid=3144 /usr/bin/sudo guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146 /tmp/sample.bin guuid=139271f8-1900-0000-de0e-67da480c0000 pid=3144->guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146 execve guuid=8de11bfc-1900-0000-de0e-67da4b0c0000 pid=3147 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=8de11bfc-1900-0000-de0e-67da4b0c0000 pid=3147 execve guuid=632b58fc-1900-0000-de0e-67da4d0c0000 pid=3149 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=632b58fc-1900-0000-de0e-67da4d0c0000 pid=3149 execve guuid=95b48ffc-1900-0000-de0e-67da4f0c0000 pid=3151 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=95b48ffc-1900-0000-de0e-67da4f0c0000 pid=3151 clone guuid=ccd8adfc-1900-0000-de0e-67da500c0000 pid=3152 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=ccd8adfc-1900-0000-de0e-67da500c0000 pid=3152 execve guuid=ca8fe2fc-1900-0000-de0e-67da510c0000 pid=3153 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=ca8fe2fc-1900-0000-de0e-67da510c0000 pid=3153 execve guuid=d4052efd-1900-0000-de0e-67da530c0000 pid=3155 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=d4052efd-1900-0000-de0e-67da530c0000 pid=3155 clone guuid=3c3949fd-1900-0000-de0e-67da550c0000 pid=3157 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=3c3949fd-1900-0000-de0e-67da550c0000 pid=3157 execve guuid=08f376fd-1900-0000-de0e-67da560c0000 pid=3158 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=08f376fd-1900-0000-de0e-67da560c0000 pid=3158 execve guuid=9d84a2fd-1900-0000-de0e-67da570c0000 pid=3159 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=9d84a2fd-1900-0000-de0e-67da570c0000 pid=3159 clone guuid=b037b0fd-1900-0000-de0e-67da590c0000 pid=3161 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=b037b0fd-1900-0000-de0e-67da590c0000 pid=3161 execve guuid=f5b4d7fd-1900-0000-de0e-67da5a0c0000 pid=3162 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=f5b4d7fd-1900-0000-de0e-67da5a0c0000 pid=3162 execve guuid=edab02fe-1900-0000-de0e-67da5c0c0000 pid=3164 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=edab02fe-1900-0000-de0e-67da5c0c0000 pid=3164 clone guuid=0e8728fe-1900-0000-de0e-67da5d0c0000 pid=3165 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=0e8728fe-1900-0000-de0e-67da5d0c0000 pid=3165 execve guuid=6ed44afe-1900-0000-de0e-67da5e0c0000 pid=3166 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=6ed44afe-1900-0000-de0e-67da5e0c0000 pid=3166 execve guuid=c20196fe-1900-0000-de0e-67da600c0000 pid=3168 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=c20196fe-1900-0000-de0e-67da600c0000 pid=3168 clone guuid=593ea0fe-1900-0000-de0e-67da610c0000 pid=3169 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=593ea0fe-1900-0000-de0e-67da610c0000 pid=3169 execve guuid=84aeccfe-1900-0000-de0e-67da630c0000 pid=3171 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=84aeccfe-1900-0000-de0e-67da630c0000 pid=3171 execve guuid=61dbf1fe-1900-0000-de0e-67da640c0000 pid=3172 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=61dbf1fe-1900-0000-de0e-67da640c0000 pid=3172 clone guuid=f3aa10ff-1900-0000-de0e-67da650c0000 pid=3173 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=f3aa10ff-1900-0000-de0e-67da650c0000 pid=3173 execve guuid=5cbe5fff-1900-0000-de0e-67da680c0000 pid=3176 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=5cbe5fff-1900-0000-de0e-67da680c0000 pid=3176 execve guuid=e0cd7fff-1900-0000-de0e-67da690c0000 pid=3177 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=e0cd7fff-1900-0000-de0e-67da690c0000 pid=3177 clone guuid=2f4d84ff-1900-0000-de0e-67da6a0c0000 pid=3178 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=2f4d84ff-1900-0000-de0e-67da6a0c0000 pid=3178 execve guuid=f0a0cdff-1900-0000-de0e-67da6b0c0000 pid=3179 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=f0a0cdff-1900-0000-de0e-67da6b0c0000 pid=3179 execve guuid=a2cd1900-1a00-0000-de0e-67da6c0c0000 pid=3180 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=a2cd1900-1a00-0000-de0e-67da6c0c0000 pid=3180 clone guuid=5a6f2700-1a00-0000-de0e-67da6d0c0000 pid=3181 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=5a6f2700-1a00-0000-de0e-67da6d0c0000 pid=3181 execve guuid=bc267700-1a00-0000-de0e-67da6e0c0000 pid=3182 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=bc267700-1a00-0000-de0e-67da6e0c0000 pid=3182 execve guuid=7102af00-1a00-0000-de0e-67da6f0c0000 pid=3183 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=7102af00-1a00-0000-de0e-67da6f0c0000 pid=3183 clone guuid=7ee8b500-1a00-0000-de0e-67da700c0000 pid=3184 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=7ee8b500-1a00-0000-de0e-67da700c0000 pid=3184 execve guuid=0db2df00-1a00-0000-de0e-67da710c0000 pid=3185 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=0db2df00-1a00-0000-de0e-67da710c0000 pid=3185 execve guuid=b9372a01-1a00-0000-de0e-67da720c0000 pid=3186 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=b9372a01-1a00-0000-de0e-67da720c0000 pid=3186 clone guuid=4bfb3b01-1a00-0000-de0e-67da730c0000 pid=3187 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=4bfb3b01-1a00-0000-de0e-67da730c0000 pid=3187 execve guuid=a8ee7301-1a00-0000-de0e-67da740c0000 pid=3188 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=a8ee7301-1a00-0000-de0e-67da740c0000 pid=3188 execve guuid=2c2ea601-1a00-0000-de0e-67da750c0000 pid=3189 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=2c2ea601-1a00-0000-de0e-67da750c0000 pid=3189 clone guuid=057faf01-1a00-0000-de0e-67da760c0000 pid=3190 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=057faf01-1a00-0000-de0e-67da760c0000 pid=3190 execve guuid=c80ae801-1a00-0000-de0e-67da770c0000 pid=3191 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=c80ae801-1a00-0000-de0e-67da770c0000 pid=3191 execve guuid=ff6b2402-1a00-0000-de0e-67da780c0000 pid=3192 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=ff6b2402-1a00-0000-de0e-67da780c0000 pid=3192 clone guuid=ee472e02-1a00-0000-de0e-67da790c0000 pid=3193 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=ee472e02-1a00-0000-de0e-67da790c0000 pid=3193 execve guuid=54a05702-1a00-0000-de0e-67da7a0c0000 pid=3194 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=54a05702-1a00-0000-de0e-67da7a0c0000 pid=3194 execve guuid=e10c8e02-1a00-0000-de0e-67da7b0c0000 pid=3195 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=e10c8e02-1a00-0000-de0e-67da7b0c0000 pid=3195 clone guuid=cbe0a302-1a00-0000-de0e-67da7c0c0000 pid=3196 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=cbe0a302-1a00-0000-de0e-67da7c0c0000 pid=3196 execve guuid=f23ddc02-1a00-0000-de0e-67da7d0c0000 pid=3197 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=f23ddc02-1a00-0000-de0e-67da7d0c0000 pid=3197 execve guuid=89e30f03-1a00-0000-de0e-67da7e0c0000 pid=3198 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=89e30f03-1a00-0000-de0e-67da7e0c0000 pid=3198 clone guuid=d0601e03-1a00-0000-de0e-67da7f0c0000 pid=3199 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=d0601e03-1a00-0000-de0e-67da7f0c0000 pid=3199 execve guuid=60a35503-1a00-0000-de0e-67da800c0000 pid=3200 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=60a35503-1a00-0000-de0e-67da800c0000 pid=3200 execve guuid=b4ac9a03-1a00-0000-de0e-67da810c0000 pid=3201 /usr/bin/dash guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=b4ac9a03-1a00-0000-de0e-67da810c0000 pid=3201 clone guuid=464db103-1a00-0000-de0e-67da820c0000 pid=3202 /usr/bin/busybox guuid=eb08ddfb-1900-0000-de0e-67da4a0c0000 pid=3146->guuid=464db103-1a00-0000-de0e-67da820c0000 pid=3202 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 673337ea6fb0eba12c2e7abe1447878e7f9ee63dad296aa8ed47578bb0c1f039

(this sample)

  
Delivery method
Distributed via web download

Comments