MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6bcae8f7016b166affdff426d2269c23feb5fcf5f482ee809976adea3e0f9453. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Sliver


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 6bcae8f7016b166affdff426d2269c23feb5fcf5f482ee809976adea3e0f9453
SHA3-384 hash: 15f91f34692c920643a8121b7e790e027e48a23afc6c032d5949971f7748f9e42a5aa1d59e876151a821f73a4559470e
SHA1 hash: f918923d18d6f01f4600d7491d62bd3bb6fde8a6
MD5 hash: 03844bf4b9b7e39a45c91aea243fccf7
humanhash: oscar-river-harry-hot
File name:script2
Download: download sample
Signature Sliver
File size:326 bytes
First seen:2025-08-23 12:19:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:A53z0wyVVKoFH4pcpmZBf+VFNaeMFIxFwK:cYB1uBHeMFIL
TLSH T1F0E04F81E8648CB5AC250C265936EF40B586ACAE9D5EBA50D4D5AF80746528C3044ED9
Magika shell
Reporter abuse_ch
Tags:sh sliver
URLMalware sample (SHA256 hash)SignatureTags
http://181.223.9.36:9000/linuxcd757c1ef9cc99018ea1ef52e85208264c2f1724470027ceabd2eabde30b7f70 SliverSliver ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
361
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=fd92c864-1900-0000-e4ad-a936be0f0000 pid=4030 /usr/bin/sudo guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036 /tmp/sample.bin guuid=fd92c864-1900-0000-e4ad-a936be0f0000 pid=4030->guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036 execve guuid=8e163d67-1900-0000-e4ad-a936c70f0000 pid=4039 /usr/bin/wget net send-data write-file guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036->guuid=8e163d67-1900-0000-e4ad-a936c70f0000 pid=4039 execve guuid=add17c2a-1b00-0000-e4ad-a9360d140000 pid=5133 /usr/bin/chmod guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036->guuid=add17c2a-1b00-0000-e4ad-a9360d140000 pid=5133 execve guuid=079dde2a-1b00-0000-e4ad-a9360f140000 pid=5135 /usr/bin/chattr guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036->guuid=079dde2a-1b00-0000-e4ad-a9360f140000 pid=5135 execve guuid=6b05e02c-1b00-0000-e4ad-a93613140000 pid=5139 /usr/bin/bash guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036->guuid=6b05e02c-1b00-0000-e4ad-a93613140000 pid=5139 clone guuid=c4aadf32-1b00-0000-e4ad-a93619140000 pid=5145 /usr/bin/bash guuid=a01d5f66-1900-0000-e4ad-a936c40f0000 pid=4036->guuid=c4aadf32-1b00-0000-e4ad-a93619140000 pid=5145 clone 46f33d1e-3df6-59cc-8ee2-420cdf0e55d8 181.223.9.36:9000 guuid=8e163d67-1900-0000-e4ad-a936c70f0000 pid=4039->46f33d1e-3df6-59cc-8ee2-420cdf0e55d8 send: 137B guuid=97eff52c-1b00-0000-e4ad-a93614140000 pid=5140 /usr/bin/ps guuid=6b05e02c-1b00-0000-e4ad-a93613140000 pid=5139->guuid=97eff52c-1b00-0000-e4ad-a93614140000 pid=5140 execve guuid=2acb022d-1b00-0000-e4ad-a93615140000 pid=5141 /usr/bin/grep guuid=6b05e02c-1b00-0000-e4ad-a93613140000 pid=5139->guuid=2acb022d-1b00-0000-e4ad-a93615140000 pid=5141 execve guuid=71283f2d-1b00-0000-e4ad-a93616140000 pid=5142 /usr/bin/wc guuid=6b05e02c-1b00-0000-e4ad-a93613140000 pid=5139->guuid=71283f2d-1b00-0000-e4ad-a93616140000 pid=5142 execve guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146 /usr/bin/linux net guuid=c4aadf32-1b00-0000-e4ad-a93619140000 pid=5145->guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146 execve a540b5d0-f675-57c0-ba6c-cf458cc16c93 181.223.9.36:8888 guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146->a540b5d0-f675-57c0-ba6c-cf458cc16c93 con guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5147 /usr/bin/linux guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146->guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5147 clone guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5148 /usr/bin/linux guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146->guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5148 clone guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5149 /usr/bin/linux guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146->guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5149 clone guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5150 /usr/bin/linux guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5146->guuid=00e1eb32-1b00-0000-e4ad-a9361a140000 pid=5150 clone
Result
Malware family:
Score:
  10/10
Tags:
family:sliver backdoor defense_evasion discovery linux persistence trojan
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Reads CPU attributes
Enumerates running processes
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Sliver RAT v2
Sliver family
SliverRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Sliver

sh 6bcae8f7016b166affdff426d2269c23feb5fcf5f482ee809976adea3e0f9453

(this sample)

  
Delivery method
Distributed via web download

Comments