MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69bb59cc250759c9cdf5b1cfe2e0aa784cb657fd9918c9a0ecb6565675332f89. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 69bb59cc250759c9cdf5b1cfe2e0aa784cb657fd9918c9a0ecb6565675332f89
SHA3-384 hash: 8ee78fca855b870701ecdc69c7bd611b3d8a1c21c4fd677af98ae7be245dffa9fdda74ab33054e54bb7845d570a6f61d
SHA1 hash: d67a1d0c2fff298b8f11be896706546598a2d4ef
MD5 hash: 670612c34788f0b9ffc4d137679cb89b
humanhash: william-music-red-robert
File name:tbk
Download: download sample
File size:677 bytes
First seen:2026-04-30 23:33:32 UTC
Last seen:2026-05-19 06:22:37 UTC
File type: sh
MIME type:text/plain
ssdeep 12:B28n+IFnGewkAOWNn+0A8nvixaGewtgAZt+JGy:IJ4nGBktDaGBeB
TLSH T1510184D10332AAA5B8267D1670B1755E63CB7FB421DC9F4CB57849A11C498F0B001BA9
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.101.153/n2/armv5lec41a35c7df2a684c7a97da730d93c63a15dc34f619474e8cc03fd7afe063ef4 Miraiarm elf mirai ua-wget

Intelligence


File Origin
# of uploads :
254
# of downloads :
10
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
text
First seen:
2026-04-25T22:36:00Z UTC
Last seen:
2026-05-02T18:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e13d666f-1b00-0000-84f0-a108ba0a0000 pid=2746 /usr/bin/sudo guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751 /tmp/sample.bin guuid=e13d666f-1b00-0000-84f0-a108ba0a0000 pid=2746->guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751 execve guuid=9a6d8f71-1b00-0000-84f0-a108c00a0000 pid=2752 /usr/bin/wget net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=9a6d8f71-1b00-0000-84f0-a108c00a0000 pid=2752 execve guuid=879d1e89-1b00-0000-84f0-a108e10a0000 pid=2785 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=879d1e89-1b00-0000-84f0-a108e10a0000 pid=2785 execve guuid=6af35e89-1b00-0000-84f0-a108e30a0000 pid=2787 /usr/bin/dash guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=6af35e89-1b00-0000-84f0-a108e30a0000 pid=2787 clone guuid=37a0088a-1b00-0000-84f0-a108e70a0000 pid=2791 /usr/bin/wget net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=37a0088a-1b00-0000-84f0-a108e70a0000 pid=2791 execve guuid=e9a9f69f-1b00-0000-84f0-a108090b0000 pid=2825 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=e9a9f69f-1b00-0000-84f0-a108090b0000 pid=2825 execve guuid=557a57a0-1b00-0000-84f0-a1080a0b0000 pid=2826 /usr/bin/dash guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=557a57a0-1b00-0000-84f0-a1080a0b0000 pid=2826 clone guuid=b6b223a1-1b00-0000-84f0-a1080d0b0000 pid=2829 /usr/bin/wget net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=b6b223a1-1b00-0000-84f0-a1080d0b0000 pid=2829 execve guuid=95e4d5b6-1b00-0000-84f0-a1083f0b0000 pid=2879 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=95e4d5b6-1b00-0000-84f0-a1083f0b0000 pid=2879 execve guuid=5d350cb7-1b00-0000-84f0-a108410b0000 pid=2881 /dev/x86 net guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=5d350cb7-1b00-0000-84f0-a108410b0000 pid=2881 execve guuid=be5260b8-1b00-0000-84f0-a108460b0000 pid=2886 /usr/bin/wget net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=be5260b8-1b00-0000-84f0-a108460b0000 pid=2886 execve guuid=6bcabfcd-1b00-0000-84f0-a108760b0000 pid=2934 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=6bcabfcd-1b00-0000-84f0-a108760b0000 pid=2934 execve guuid=15e618ce-1b00-0000-84f0-a108770b0000 pid=2935 /usr/bin/dash guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=15e618ce-1b00-0000-84f0-a108770b0000 pid=2935 clone guuid=04334ad0-1b00-0000-84f0-a1087d0b0000 pid=2941 /usr/bin/rm delete-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=04334ad0-1b00-0000-84f0-a1087d0b0000 pid=2941 execve guuid=63c2bed0-1b00-0000-84f0-a1087f0b0000 pid=2943 /usr/bin/busybox net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=63c2bed0-1b00-0000-84f0-a1087f0b0000 pid=2943 execve guuid=763643e5-1b00-0000-84f0-a108b10b0000 pid=2993 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=763643e5-1b00-0000-84f0-a108b10b0000 pid=2993 execve guuid=d2608be5-1b00-0000-84f0-a108b30b0000 pid=2995 /usr/bin/dash guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=d2608be5-1b00-0000-84f0-a108b30b0000 pid=2995 clone guuid=0c9227e6-1b00-0000-84f0-a108b70b0000 pid=2999 /usr/bin/busybox net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=0c9227e6-1b00-0000-84f0-a108b70b0000 pid=2999 execve guuid=48027ffa-1b00-0000-84f0-a108eb0b0000 pid=3051 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=48027ffa-1b00-0000-84f0-a108eb0b0000 pid=3051 execve guuid=5334bafa-1b00-0000-84f0-a108ed0b0000 pid=3053 /usr/bin/dash guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=5334bafa-1b00-0000-84f0-a108ed0b0000 pid=3053 clone guuid=dfe156fb-1b00-0000-84f0-a108f00b0000 pid=3056 /usr/bin/busybox net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=dfe156fb-1b00-0000-84f0-a108f00b0000 pid=3056 execve guuid=5450c20f-1c00-0000-84f0-a1082c0c0000 pid=3116 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=5450c20f-1c00-0000-84f0-a1082c0c0000 pid=3116 execve guuid=31d60210-1c00-0000-84f0-a1082d0c0000 pid=3117 /dev/x86 net guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=31d60210-1c00-0000-84f0-a1082d0c0000 pid=3117 execve guuid=4dfbd410-1c00-0000-84f0-a108310c0000 pid=3121 /usr/bin/busybox net send-data write-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=4dfbd410-1c00-0000-84f0-a108310c0000 pid=3121 execve guuid=f3043925-1c00-0000-84f0-a108690c0000 pid=3177 /usr/bin/chmod guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=f3043925-1c00-0000-84f0-a108690c0000 pid=3177 execve guuid=2ef09925-1c00-0000-84f0-a1086b0c0000 pid=3179 /usr/bin/dash guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=2ef09925-1c00-0000-84f0-a1086b0c0000 pid=3179 clone guuid=d5c12e26-1c00-0000-84f0-a1086f0c0000 pid=3183 /usr/bin/rm delete-file guuid=200c3071-1b00-0000-84f0-a108bf0a0000 pid=2751->guuid=d5c12e26-1c00-0000-84f0-a1086f0c0000 pid=3183 execve 878b6614-6e66-5c2d-8323-6325abb24bfa 162.248.101.153:80 guuid=9a6d8f71-1b00-0000-84f0-a108c00a0000 pid=2752->878b6614-6e66-5c2d-8323-6325abb24bfa send: 137B guuid=37a0088a-1b00-0000-84f0-a108e70a0000 pid=2791->878b6614-6e66-5c2d-8323-6325abb24bfa send: 137B guuid=b6b223a1-1b00-0000-84f0-a1080d0b0000 pid=2829->878b6614-6e66-5c2d-8323-6325abb24bfa send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5d350cb7-1b00-0000-84f0-a108410b0000 pid=2881->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885 /dev/x86 dns net send-data zombie guuid=5d350cb7-1b00-0000-84f0-a108410b0000 pid=2881->guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885 clone 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885->54d92a3b-1447-55af-b534-047898c60c8d send: 31B 0eb9ed59-9f77-5fbe-8b9c-fce5a6e3d1d4 higher.makeup:25565 guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885->0eb9ed59-9f77-5fbe-8b9c-fce5a6e3d1d4 send: 8B 4f156124-7d4d-52d3-8491-35b2fcd90a07 higher.makeup:123 guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885->4f156124-7d4d-52d3-8491-35b2fcd90a07 send: 2B b36cadc9-b0a0-51ee-bcf9-b2f778f87925 higher.makeup:8080 guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885->b36cadc9-b0a0-51ee-bcf9-b2f778f87925 con guuid=888867b8-1b00-0000-84f0-a108470b0000 pid=2887 /dev/x86 guuid=25c659b8-1b00-0000-84f0-a108450b0000 pid=2885->guuid=888867b8-1b00-0000-84f0-a108470b0000 pid=2887 clone guuid=be5260b8-1b00-0000-84f0-a108460b0000 pid=2886->878b6614-6e66-5c2d-8323-6325abb24bfa send: 139B guuid=b13773b8-1b00-0000-84f0-a108480b0000 pid=2888 /dev/x86 send-data guuid=888867b8-1b00-0000-84f0-a108470b0000 pid=2887->guuid=b13773b8-1b00-0000-84f0-a108480b0000 pid=2888 clone 00643b16-1df6-5e07-aaf9-1a58b9029caf 127.0.0.1:51050 guuid=b13773b8-1b00-0000-84f0-a108480b0000 pid=2888->00643b16-1df6-5e07-aaf9-1a58b9029caf send: 1B guuid=63c2bed0-1b00-0000-84f0-a1087f0b0000 pid=2943->878b6614-6e66-5c2d-8323-6325abb24bfa send: 85B guuid=0c9227e6-1b00-0000-84f0-a108b70b0000 pid=2999->878b6614-6e66-5c2d-8323-6325abb24bfa send: 85B guuid=dfe156fb-1b00-0000-84f0-a108f00b0000 pid=3056->878b6614-6e66-5c2d-8323-6325abb24bfa send: 84B guuid=31d60210-1c00-0000-84f0-a1082d0c0000 pid=3117->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce0fce10-1c00-0000-84f0-a108300c0000 pid=3120 /dev/x86 net send-data zombie guuid=31d60210-1c00-0000-84f0-a1082d0c0000 pid=3117->guuid=ce0fce10-1c00-0000-84f0-a108300c0000 pid=3120 clone 307db2dd-32a0-52fe-a412-5478b0ff6eae 127.0.0.1:63464 guuid=ce0fce10-1c00-0000-84f0-a108300c0000 pid=3120->307db2dd-32a0-52fe-a412-5478b0ff6eae send: 2B guuid=4dfbd410-1c00-0000-84f0-a108310c0000 pid=3121->878b6614-6e66-5c2d-8323-6325abb24bfa send: 87B
Gathering data
Threat name:
Script.Downloader.Heuristic
Status:
Malicious
First seen:
2026-04-26 03:25:24 UTC
File Type:
Text (Shell)
AV detection:
6 of 38 (15.79%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 69bb59cc250759c9cdf5b1cfe2e0aa784cb657fd9918c9a0ecb6565675332f89

(this sample)

  
Delivery method
Distributed via web download

Comments