MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f2f464e992c5ae5bd5e94ed236e6d30ff82985dfdfa68c87df10195e75000af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 6f2f464e992c5ae5bd5e94ed236e6d30ff82985dfdfa68c87df10195e75000af
SHA3-384 hash: c558cc0137d4b259b5e9b0ea1c073292cad359965e3a9cfea6004b55f32100317d0aad490cce7a3d4fdea2cf4f76d5a6
SHA1 hash: f61d4a97ac53be351096732a481b50f7311e89b0
MD5 hash: 55edb851f0df88c83a14f27bf9f308a6
humanhash: fanta-mike-carbon-ack
File name:check.sh
Download: download sample
File size:118 bytes
First seen:2026-06-16 15:19:01 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:Q1iLDgVTLFftHpFDzCLDgVTLFftHDOOdom2CaYyERv:ooDgVHFftp1IDgVHFftD8m2CaYp
TLSH T177B092F90C305D4E8001C5CB73B00606A0216DCF6DFF42DCA99507B9000E487FE06E00
Magika batch
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=3c3d4433-1a00-0000-f905-2b6f4b080000 pid=2123 /usr/bin/sudo guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130 /tmp/sample.bin guuid=3c3d4433-1a00-0000-f905-2b6f4b080000 pid=2123->guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130 execve guuid=11097136-1a00-0000-f905-2b6f54080000 pid=2132 /usr/bin/wget net send-data write-file guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130->guuid=11097136-1a00-0000-f905-2b6f54080000 pid=2132 execve guuid=4361dc4d-1a00-0000-f905-2b6f86080000 pid=2182 /usr/bin/curl net send-data write-file guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130->guuid=4361dc4d-1a00-0000-f905-2b6f86080000 pid=2182 execve guuid=17619971-1a00-0000-f905-2b6fc8080000 pid=2248 /usr/bin/chmod guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130->guuid=17619971-1a00-0000-f905-2b6fc8080000 pid=2248 execve guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250 /tmp/boss guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130->guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250 execve guuid=77930112-1b00-0000-f905-2b6f590a0000 pid=2649 /usr/bin/rm delete-file guuid=04400c36-1a00-0000-f905-2b6f52080000 pid=2130->guuid=77930112-1b00-0000-f905-2b6f590a0000 pid=2649 execve ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 94.26.106.195:80 guuid=11097136-1a00-0000-f905-2b6f54080000 pid=2132->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 132B guuid=4361dc4d-1a00-0000-f905-2b6f86080000 pid=2182->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 81B guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2257 /tmp/boss guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250->guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2257 clone guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2258 /tmp/boss guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250->guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2258 clone guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259 /tmp/boss write-config guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250->guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259 clone guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2260 /tmp/boss guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250->guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2260 clone guuid=28013c77-1a00-0000-f905-2b6fd5080000 pid=2261 /tmp/boss guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250->guuid=28013c77-1a00-0000-f905-2b6fd5080000 pid=2261 clone guuid=f2cd4277-1a00-0000-f905-2b6fd6080000 pid=2262 /usr/bin/uname guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2250->guuid=f2cd4277-1a00-0000-f905-2b6fd6080000 pid=2262 execve guuid=f2d29577-1a00-0000-f905-2b6fd7080000 pid=2263 /usr/bin/chmod guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=f2d29577-1a00-0000-f905-2b6fd7080000 pid=2263 execve guuid=aefa6796-1a00-0000-f905-2b6f15090000 pid=2325 /usr/bin/systemctl guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=aefa6796-1a00-0000-f905-2b6f15090000 pid=2325 execve guuid=45c7fed5-1a00-0000-f905-2b6f9f090000 pid=2463 /usr/bin/systemctl guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=45c7fed5-1a00-0000-f905-2b6f9f090000 pid=2463 execve guuid=5043bf05-1b00-0000-f905-2b6f240a0000 pid=2596 /usr/bin/systemctl guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=5043bf05-1b00-0000-f905-2b6f240a0000 pid=2596 execve guuid=dd0f3409-1b00-0000-f905-2b6f320a0000 pid=2610 /usr/bin/pgrep guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=dd0f3409-1b00-0000-f905-2b6f320a0000 pid=2610 execve guuid=dd2f3f0d-1b00-0000-f905-2b6f440a0000 pid=2628 /usr/bin/bash guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=dd2f3f0d-1b00-0000-f905-2b6f440a0000 pid=2628 execve guuid=b3da880e-1b00-0000-f905-2b6f4c0a0000 pid=2636 /usr/bin/bash guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=b3da880e-1b00-0000-f905-2b6f4c0a0000 pid=2636 execve guuid=38b44d0f-1b00-0000-f905-2b6f4e0a0000 pid=2638 /usr/bin/rm delete-file guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=38b44d0f-1b00-0000-f905-2b6f4e0a0000 pid=2638 execve guuid=bef4e611-1b00-0000-f905-2b6f580a0000 pid=2648 /usr/bin/bash zombie guuid=9a40ea71-1a00-0000-f905-2b6fca080000 pid=2259->guuid=bef4e611-1b00-0000-f905-2b6f580a0000 pid=2648 execve guuid=ca1d5d78-1a00-0000-f905-2b6fd9080000 pid=2265 /usr/bin/curl net send-data write-file guuid=f2d29577-1a00-0000-f905-2b6fd7080000 pid=2263->guuid=ca1d5d78-1a00-0000-f905-2b6fd9080000 pid=2265 execve a633da7e-6415-55fb-93ef-5ee209767fd5 2.57.241.243:80 guuid=ca1d5d78-1a00-0000-f905-2b6fd9080000 pid=2265->a633da7e-6415-55fb-93ef-5ee209767fd5 send: 82B guuid=0716a60d-1b00-0000-f905-2b6f460a0000 pid=2630 /usr/bin/rm delete-file guuid=dd2f3f0d-1b00-0000-f905-2b6f440a0000 pid=2628->guuid=0716a60d-1b00-0000-f905-2b6f460a0000 pid=2630 execve guuid=9460f50d-1b00-0000-f905-2b6f480a0000 pid=2632 /usr/bin/rm delete-file guuid=dd2f3f0d-1b00-0000-f905-2b6f440a0000 pid=2628->guuid=9460f50d-1b00-0000-f905-2b6f480a0000 pid=2632 execve guuid=bbd73a0e-1b00-0000-f905-2b6f4a0a0000 pid=2634 /usr/bin/rm guuid=dd2f3f0d-1b00-0000-f905-2b6f440a0000 pid=2628->guuid=bbd73a0e-1b00-0000-f905-2b6f4a0a0000 pid=2634 execve guuid=0e703412-1b00-0000-f905-2b6f5a0a0000 pid=2650 /usr/bin/bash zombie guuid=bef4e611-1b00-0000-f905-2b6f580a0000 pid=2648->guuid=0e703412-1b00-0000-f905-2b6f5a0a0000 pid=2650 clone guuid=ee175a12-1b00-0000-f905-2b6f5c0a0000 pid=2652 /usr/bin/wget net send-data write-file guuid=0e703412-1b00-0000-f905-2b6f5a0a0000 pid=2650->guuid=ee175a12-1b00-0000-f905-2b6f5c0a0000 pid=2652 execve guuid=02ed9114-1b00-0000-f905-2b6f620a0000 pid=2658 /usr/bin/curl net send-data write-file guuid=0e703412-1b00-0000-f905-2b6f5a0a0000 pid=2650->guuid=02ed9114-1b00-0000-f905-2b6f620a0000 pid=2658 execve guuid=d71f2e17-1b00-0000-f905-2b6f690a0000 pid=2665 /usr/bin/chmod guuid=0e703412-1b00-0000-f905-2b6f5a0a0000 pid=2650->guuid=d71f2e17-1b00-0000-f905-2b6f690a0000 pid=2665 execve guuid=ecf17717-1b00-0000-f905-2b6f6a0a0000 pid=2666 /usr/bin/bash guuid=0e703412-1b00-0000-f905-2b6f5a0a0000 pid=2650->guuid=ecf17717-1b00-0000-f905-2b6f6a0a0000 pid=2666 clone guuid=ee175a12-1b00-0000-f905-2b6f5c0a0000 pid=2652->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 133B guuid=02ed9114-1b00-0000-f905-2b6f620a0000 pid=2658->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 82B guuid=d6a7a617-1b00-0000-f905-2b6f6c0a0000 pid=2668 /usr/bin/curl net send-data write-file guuid=ecf17717-1b00-0000-f905-2b6f6a0a0000 pid=2666->guuid=d6a7a617-1b00-0000-f905-2b6f6c0a0000 pid=2668 execve guuid=db20e42b-1b00-0000-f905-2b6f9a0a0000 pid=2714 /usr/bin/wget net send-data write-file guuid=ecf17717-1b00-0000-f905-2b6f6a0a0000 pid=2666->guuid=db20e42b-1b00-0000-f905-2b6f9a0a0000 pid=2714 execve guuid=ffe3423f-1b00-0000-f905-2b6fca0a0000 pid=2762 /usr/bin/chmod guuid=ecf17717-1b00-0000-f905-2b6f6a0a0000 pid=2666->guuid=ffe3423f-1b00-0000-f905-2b6fca0a0000 pid=2762 execve guuid=2c50b43f-1b00-0000-f905-2b6fcc0a0000 pid=2764 /var/tmp/cli write-file zombie guuid=ecf17717-1b00-0000-f905-2b6f6a0a0000 pid=2666->guuid=2c50b43f-1b00-0000-f905-2b6fcc0a0000 pid=2764 execve guuid=d6a7a617-1b00-0000-f905-2b6f6c0a0000 pid=2668->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 80B guuid=db20e42b-1b00-0000-f905-2b6f9a0a0000 pid=2714->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 131B guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059 /tmp/filev4kAXr write-file guuid=2c50b43f-1b00-0000-f905-2b6fcc0a0000 pid=2764->guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059 execve guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3067 /tmp/filev4kAXr net send-data guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059->guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3067 clone guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3068 /tmp/filev4kAXr net send-data guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059->guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3068 clone guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3069 /tmp/filev4kAXr net send-data guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059->guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3069 clone guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3071 /tmp/filev4kAXr net send-data guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059->guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3071 clone guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3072 /tmp/filev4kAXr dns send-data guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3059->guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3072 clone 3947dbfc-63e9-5dad-b623-38c58f86ebd1 srv8.traffmonetizer.com:769 guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3067->3947dbfc-63e9-5dad-b623-38c58f86ebd1 con 6524b935-78ea-587e-b913-eb3f81629f0d srv2.traffmonetizer.com:80 guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3067->6524b935-78ea-587e-b913-eb3f81629f0d con 253ec59a-6bd7-5caa-9cb8-d19ef46b6867 blnc.traffmonetizer.com:443 guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3067->253ec59a-6bd7-5caa-9cb8-d19ef46b6867 send: 482B 0c05d9de-a3f3-59eb-bfd5-51e0800a2c97 srv2.traffmonetizer.com:769 guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3067->0c05d9de-a3f3-59eb-bfd5-51e0800a2c97 send: 1306B guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3068->3947dbfc-63e9-5dad-b623-38c58f86ebd1 send: 336B guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3068->6524b935-78ea-587e-b913-eb3f81629f0d send: 111B guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3068->253ec59a-6bd7-5caa-9cb8-d19ef46b6867 con guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3068->0c05d9de-a3f3-59eb-bfd5-51e0800a2c97 send: 1055967B guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3069->3947dbfc-63e9-5dad-b623-38c58f86ebd1 con guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3069->253ec59a-6bd7-5caa-9cb8-d19ef46b6867 send: 482B guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3069->0c05d9de-a3f3-59eb-bfd5-51e0800a2c97 con guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3071->253ec59a-6bd7-5caa-9cb8-d19ef46b6867 con guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3071->0c05d9de-a3f3-59eb-bfd5-51e0800a2c97 send: 178B 49bfe7f9-096a-509b-8046-ab73abcb8da3 srv2.traffmonetizer.com:711 guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3071->49bfe7f9-096a-509b-8046-ab73abcb8da3 send: 4B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=511d06d9-1b00-0000-f905-2b6ff30b0000 pid=3072->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 492B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6f2f464e992c5ae5bd5e94ed236e6d30ff82985dfdfa68c87df10195e75000af

(this sample)

  
Delivery method
Distributed via web download

Comments