MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 67e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 6
| SHA256 hash: | 67e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203 |
|---|---|
| SHA3-384 hash: | 450b190c898b1ae5452826f81a8ac3e79051bb585d8f32b61b016925b3d992bcc2d478a1877c2022105ab0d7c704cb04 |
| SHA1 hash: | c629833b1256a5fff81479a7d2bf19fa7d0a8c79 |
| MD5 hash: | aa62fccb02efdc7345711f72d6641a5f |
| humanhash: | batman-saturn-chicken-kitten |
| File name: | cccc.sh |
| Download: | download sample |
| File size: | 2'018 bytes |
| First seen: | 2026-03-28 13:47:58 UTC |
| Last seen: | 2026-03-28 20:41:10 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 48:aFRfBvNuufHMzQKFGXx3wSTEYLHvHpO8OSI4QiY2Xx30XWB:wRZvNuufM+EXZWB |
| TLSH | T16C416B4E4F46D0E1628024FC674F3D86B88705EF91158104F79EBB8BAFB4711E2889D6 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Intelligence
File Origin
# of uploads :
2
# of downloads :
49
Origin country :
DEVendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-27T19:15:00Z UTC
Last seen:
2026-03-28T08:01:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
24%
Verdict:
Benign
File Type:
SCRIPT
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Text.Browser.Generic
Status:
Suspicious
First seen:
2026-03-27 22:37:45 UTC
File Type:
Text (Shell)
AV detection:
1 of 36 (2.78%)
Threat level:
4/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Modifies Bash startup script
Creates/modifies environment variables
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh 67e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.