MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72ec88c4f57ff222abe8a49809e149cb68daa1bbf77147b946f3e0cbfcf411ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 72ec88c4f57ff222abe8a49809e149cb68daa1bbf77147b946f3e0cbfcf411ae
SHA3-384 hash: dbabc19d053e352fef86d550a3e06990eb62522d31573d8a167cb5abf158a215d4e64e49d6a8d82a26a7d0ceade2c589
SHA1 hash: 85948e667217e3dbf8becb36eabcd857253853cb
MD5 hash: fca6874f22bc1c49489c4274ab18db71
humanhash: mexico-beryllium-spaghetti-cold
File name:cr.sh
Download: download sample
File size:4'306 bytes
First seen:2026-01-24 21:08:35 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:mhiSGbe3gp3WahvBzIX0bd0NNFGcrcBc3gjXuc2a:mhiSmeQpPpi0bONNFGzJuC
TLSH T1C791FEBD7154CAB02988D078127DCC4CED5F1D1BF296E40B720FA9A43F1A76992BC394
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://34.70.205.211/plugins-dist/safehtml/lang/font/kworkern/an/ash ua-wget
http://38.150.0.118/dewfhuewr4r89/98hy67//kworkern/an/ash ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-19T11:19:00Z UTC
Last seen:
2026-01-21T15:43:00Z UTC
Hits:
~10
Verdict:
Malicious
Threat:
Trojan-Dropper.Shell.Agent
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-01-24 21:09:48 UTC
File Type:
Text (Shell)
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Reads CPU attributes
Disables SELinux
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 72ec88c4f57ff222abe8a49809e149cb68daa1bbf77147b946f3e0cbfcf411ae

(this sample)

  
Delivery method
Distributed via web download

Comments