MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 67e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 67e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203
SHA3-384 hash: 450b190c898b1ae5452826f81a8ac3e79051bb585d8f32b61b016925b3d992bcc2d478a1877c2022105ab0d7c704cb04
SHA1 hash: c629833b1256a5fff81479a7d2bf19fa7d0a8c79
MD5 hash: aa62fccb02efdc7345711f72d6641a5f
humanhash: batman-saturn-chicken-kitten
File name:cccc.sh
Download: download sample
File size:2'018 bytes
First seen:2026-03-28 13:47:58 UTC
Last seen:2026-03-28 20:41:10 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:aFRfBvNuufHMzQKFGXx3wSTEYLHvHpO8OSI4QiY2Xx30XWB:wRZvNuufM+EXZWB
TLSH T16C416B4E4F46D0E1628024FC674F3D86B88705EF91158104F79EBB8BAFB4711E2889D6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-27T19:15:00Z UTC
Last seen:
2026-03-28T08:01:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5a9791eb-1600-0000-e186-de99880e0000 pid=3720 /usr/bin/sudo guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732 /tmp/sample.bin guuid=5a9791eb-1600-0000-e186-de99880e0000 pid=3720->guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732 execve guuid=3943bded-1600-0000-e186-de99950e0000 pid=3733 /usr/bin/dash guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=3943bded-1600-0000-e186-de99950e0000 pid=3733 clone guuid=7bbb15ee-1600-0000-e186-de99990e0000 pid=3737 /usr/bin/dash guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=7bbb15ee-1600-0000-e186-de99990e0000 pid=3737 clone guuid=13a85fee-1600-0000-e186-de999c0e0000 pid=3740 /usr/bin/rm guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=13a85fee-1600-0000-e186-de999c0e0000 pid=3740 execve guuid=8f799dee-1600-0000-e186-de999e0e0000 pid=3742 /usr/bin/wget dns net send-data write-file guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=8f799dee-1600-0000-e186-de999e0e0000 pid=3742 execve guuid=a2bce023-1700-0000-e186-de99590f0000 pid=3929 /usr/bin/chmod guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=a2bce023-1700-0000-e186-de99590f0000 pid=3929 execve guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931 /home/sandbox/linux_amd64 zombie guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931 execve guuid=29782824-1700-0000-e186-de995d0f0000 pid=3933 /usr/bin/dash guuid=687e86ed-1600-0000-e186-de99940e0000 pid=3732->guuid=29782824-1700-0000-e186-de995d0f0000 pid=3933 clone guuid=b695c6ed-1600-0000-e186-de99960e0000 pid=3734 /usr/bin/uname guuid=3943bded-1600-0000-e186-de99950e0000 pid=3733->guuid=b695c6ed-1600-0000-e186-de99960e0000 pid=3734 execve guuid=94351eee-1600-0000-e186-de999b0e0000 pid=3739 /usr/bin/uname guuid=7bbb15ee-1600-0000-e186-de99990e0000 pid=3737->guuid=94351eee-1600-0000-e186-de999b0e0000 pid=3739 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=8f799dee-1600-0000-e186-de999e0e0000 pid=3742->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 66B cc8edb27-36d3-5c2c-9dbc-39829fb8db5d quwmjfv6.seckd-cname.com:80 guuid=8f799dee-1600-0000-e186-de999e0e0000 pid=3742->cc8edb27-36d3-5c2c-9dbc-39829fb8db5d send: 145B guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3950 /home/sandbox/linux_amd64 guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931->guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3950 clone guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3951 /home/sandbox/linux_amd64 guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931->guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3951 clone guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3952 /home/sandbox/linux_amd64 guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931->guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3952 clone guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3953 /home/sandbox/linux_amd64 guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931->guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3953 clone guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955 /home/sandbox/linux_amd64 delete-file write-config write-file zombie guuid=27b52224-1700-0000-e186-de995b0f0000 pid=3931->guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955 execve guuid=a3436524-1700-0000-e186-de99600f0000 pid=3936 /usr/bin/sleep guuid=29782824-1700-0000-e186-de995d0f0000 pid=3933->guuid=a3436524-1700-0000-e186-de99600f0000 pid=3936 execve guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3959 /home/sandbox/linux_amd64 zombie guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3959 clone guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3960 /home/sandbox/linux_amd64 guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3960 clone guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3961 /home/sandbox/linux_amd64 zombie guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3961 clone guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3962 /home/sandbox/linux_amd64 guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3962 clone guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3963 /home/sandbox/linux_amd64 guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3963 clone guuid=75b39738-1700-0000-e186-de999e0f0000 pid=3998 /usr/bin/dash guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=75b39738-1700-0000-e186-de999e0f0000 pid=3998 execve guuid=0d0af038-1700-0000-e186-de99a30f0000 pid=4003 /usr/bin/systemctl guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=0d0af038-1700-0000-e186-de99a30f0000 pid=4003 execve guuid=da300868-1700-0000-e186-de9966100000 pid=4198 /usr/bin/systemctl guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=da300868-1700-0000-e186-de9966100000 pid=4198 execve guuid=9ae0ec95-1700-0000-e186-de9936110000 pid=4406 /usr/bin/systemctl guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=9ae0ec95-1700-0000-e186-de9936110000 pid=4406 execve guuid=57d2f09e-1700-0000-e186-de9962110000 pid=4450 /usr/sbin/update-rc.d guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=57d2f09e-1700-0000-e186-de9962110000 pid=4450 execve guuid=8c7da4d8-1700-0000-e186-de9905120000 pid=4613 /usr/sbin/update-rc.d guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=8c7da4d8-1700-0000-e186-de9905120000 pid=4613 execve guuid=34aa9b0e-1800-0000-e186-de99b9120000 pid=4793 /etc/init.d/systemd-logind guuid=c5f0cc28-1700-0000-e186-de99730f0000 pid=3955->guuid=34aa9b0e-1800-0000-e186-de99b9120000 pid=4793 execve guuid=394fcc38-1700-0000-e186-de99a00f0000 pid=4000 /boot/System zombie guuid=75b39738-1700-0000-e186-de999e0f0000 pid=3998->guuid=394fcc38-1700-0000-e186-de99a00f0000 pid=4000 execve guuid=ba231039-1700-0000-e186-de99a40f0000 pid=4004 /usr/bin/sleep guuid=394fcc38-1700-0000-e186-de99a00f0000 pid=4000->guuid=ba231039-1700-0000-e186-de99a40f0000 pid=4004 execve guuid=80ef9689-2000-0000-e186-de9980150000 pid=5504 /boot/System.img-6.8.0-8 delete-file write-file guuid=394fcc38-1700-0000-e186-de99a00f0000 pid=4000->guuid=80ef9689-2000-0000-e186-de9980150000 pid=5504 execve guuid=d507f28a-2000-0000-e186-de9985150000 pid=5509 /usr/bin/sleep guuid=394fcc38-1700-0000-e186-de99a00f0000 pid=4000->guuid=d507f28a-2000-0000-e186-de9985150000 pid=5509 execve guuid=92206aa2-1700-0000-e186-de996c110000 pid=4460 /usr/bin/systemctl guuid=57d2f09e-1700-0000-e186-de9962110000 pid=4450->guuid=92206aa2-1700-0000-e186-de996c110000 pid=4460 execve guuid=e2f308db-1700-0000-e186-de990c120000 pid=4620 /usr/bin/systemctl guuid=8c7da4d8-1700-0000-e186-de9905120000 pid=4613->guuid=e2f308db-1700-0000-e186-de990c120000 pid=4620 execve guuid=5f7517dc-1700-0000-e186-de9913120000 pid=4627 /usr/bin/systemctl guuid=8c7da4d8-1700-0000-e186-de9905120000 pid=4613->guuid=5f7517dc-1700-0000-e186-de9913120000 pid=4627 execve guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794 /boot/System.img-6.8.0-8 delete-file write-file guuid=34aa9b0e-1800-0000-e186-de99b9120000 pid=4793->guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794 execve guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4798 /boot/System.img-6.8.0-8 guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794->guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4798 clone guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4799 /boot/System.img-6.8.0-8 guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794->guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4799 clone guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4800 /boot/System.img-6.8.0-8 guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794->guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4800 clone guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4801 /boot/System.img-6.8.0-8 guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794->guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4801 clone guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4803 /boot/System.img-6.8.0-8 guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4794->guuid=388fc50e-1800-0000-e186-de99ba120000 pid=4803 clone guuid=80ef9689-2000-0000-e186-de9980150000 pid=5505 /boot/System.img-6.8.0-8 guuid=80ef9689-2000-0000-e186-de9980150000 pid=5504->guuid=80ef9689-2000-0000-e186-de9980150000 pid=5505 clone guuid=80ef9689-2000-0000-e186-de9980150000 pid=5506 /boot/System.img-6.8.0-8 guuid=80ef9689-2000-0000-e186-de9980150000 pid=5504->guuid=80ef9689-2000-0000-e186-de9980150000 pid=5506 clone guuid=80ef9689-2000-0000-e186-de9980150000 pid=5507 /boot/System.img-6.8.0-8 guuid=80ef9689-2000-0000-e186-de9980150000 pid=5504->guuid=80ef9689-2000-0000-e186-de9980150000 pid=5507 clone guuid=80ef9689-2000-0000-e186-de9980150000 pid=5508 /boot/System.img-6.8.0-8 guuid=80ef9689-2000-0000-e186-de9980150000 pid=5504->guuid=80ef9689-2000-0000-e186-de9980150000 pid=5508 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Text.Browser.Generic
Status:
Suspicious
First seen:
2026-03-27 22:37:45 UTC
File Type:
Text (Shell)
AV detection:
1 of 36 (2.78%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Modifies Bash startup script
Creates/modifies environment variables
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 67e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203

(this sample)

  
Delivery method
Distributed via web download

Comments