🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 729a2102bb790a128fbd8df95caf3aeb28cb0e2a855ffafafc14637f162f866c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 729a2102bb790a128fbd8df95caf3aeb28cb0e2a855ffafafc14637f162f866c
SHA3-384 hash: af90def0b31b4b9a322b70d775b358b364353131d061e0613998f30f67fccbfba1338f4997760ba9c6cbea65f07ebd39
SHA1 hash: 8d5330b028e6ee4c486612476c2c600c0ca4e04d
MD5 hash: 1151fa1d2dc317ef6c18bd34e7404368
humanhash: bakerloo-indigo-butter-coffee
File name:729a2102bb790a128fbd8df95caf3aeb28cb0e2a855ffafafc14637f162f866c
Download: download sample
File size:1'502 bytes
First seen:2026-10-02 04:34:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:gC2WwFF/wAEkgUz9QkR8mFyXH0KdOJkaBpPe1oFZyOsYXkELomzByYJOJcJd5:gCuYAEkgUz9QkRJFj4EsMZrXkEL/BzJf
TLSH T13C31ABE7F82145B3719B903C6EAEA48076866A170D247C26384EBC5A3F38468B5A1B17
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter asandov
Tags:adbhoney honeypot sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
11
Origin country :
JP JP
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-26T14:10:00Z UTC
Last seen:
2026-10-02T05:35:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=35a17ee3-1b00-0000-483d-73fb9d0b0000 pid=2973 /usr/bin/sudo guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985 /tmp/sample.bin guuid=35a17ee3-1b00-0000-483d-73fb9d0b0000 pid=2973->guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985 execve guuid=29665eeb-1b00-0000-483d-73fbab0b0000 pid=2987 /usr/bin/uname guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985->guuid=29665eeb-1b00-0000-483d-73fbab0b0000 pid=2987 execve guuid=265644ec-1b00-0000-483d-73fbad0b0000 pid=2989 /usr/bin/touch guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985->guuid=265644ec-1b00-0000-483d-73fbad0b0000 pid=2989 execve guuid=4a8219ed-1b00-0000-483d-73fbae0b0000 pid=2990 /usr/bin/rm delete-file guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985->guuid=4a8219ed-1b00-0000-483d-73fbae0b0000 pid=2990 execve guuid=c3c828ef-1b00-0000-483d-73fbb20b0000 pid=2994 /usr/bin/rm guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985->guuid=c3c828ef-1b00-0000-483d-73fbb20b0000 pid=2994 execve guuid=d094c7ef-1b00-0000-483d-73fbb40b0000 pid=2996 /usr/bin/wget net guuid=9af195ea-1b00-0000-483d-73fba90b0000 pid=2985->guuid=d094c7ef-1b00-0000-483d-73fbb40b0000 pid=2996 execve 6e045cb8-5493-502b-aec3-239eb853f873 217.60.103.135:80 guuid=d094c7ef-1b00-0000-483d-73fbb40b0000 pid=2996->6e045cb8-5493-502b-aec3-239eb853f873 con
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments