MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 74ca82a10e5e8697db96b8cb28280ff9fd0371eaafa32eb1d785320b962e19f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 6 File information Comments

SHA256 hash: 74ca82a10e5e8697db96b8cb28280ff9fd0371eaafa32eb1d785320b962e19f4
SHA3-384 hash: 981709404cfd2f64883a3a929be1cde1dedd5e206c1bd95bff77a49bab658f7b3961751683d17599b2e6477560005bdf
SHA1 hash: 0a1fb016bd10bac5455175c79aa4511e5ff1a330
MD5 hash: 484a6686325f7460349208e736433288
humanhash: tennis-six-winner-emma
File name:0a1fb016bd10bac5455175c79aa4511e5ff1a330
Download: download sample
File size:85'680 bytes
First seen:2026-07-30 09:40:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 1536:pDitm7oIt8TlUaNlgA8GYHw+X3n73z3Quw8q:R/7oZkN7jguQ
TLSH T14083197565481AB03B5BC17D9DD69514620F3D1B18A63420F2EEB28C1F7D320F1BABAD
TrID 70.0% (.) Unix-like shebang (var.1) (gen) (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin stealer
Verdict:
Adware
File Type:
unix shell
First seen:
2026-07-18T16:48:00Z UTC
Last seen:
2026-07-31T22:20:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=df4513ba-1a00-0000-5cd0-aa7f5c090000 pid=2396 /usr/bin/sudo guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400 /usr/bin/bash guuid=df4513ba-1a00-0000-5cd0-aa7f5c090000 pid=2396->guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400 execve guuid=cf9e3fbf-1a00-0000-5cd0-aa7f62090000 pid=2402 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=cf9e3fbf-1a00-0000-5cd0-aa7f62090000 pid=2402 clone guuid=345942c0-1a00-0000-5cd0-aa7f66090000 pid=2406 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=345942c0-1a00-0000-5cd0-aa7f66090000 pid=2406 clone guuid=73315cc1-1a00-0000-5cd0-aa7f6b090000 pid=2411 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=73315cc1-1a00-0000-5cd0-aa7f6b090000 pid=2411 clone guuid=73393bc2-1a00-0000-5cd0-aa7f6f090000 pid=2415 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=73393bc2-1a00-0000-5cd0-aa7f6f090000 pid=2415 clone guuid=904885c3-1a00-0000-5cd0-aa7f75090000 pid=2421 /usr/bin/dirname guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=904885c3-1a00-0000-5cd0-aa7f75090000 pid=2421 execve guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422 clone guuid=36a945e2-1a00-0000-5cd0-aa7f98090000 pid=2456 /usr/bin/uname guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=36a945e2-1a00-0000-5cd0-aa7f98090000 pid=2456 execve guuid=5bb698e2-1a00-0000-5cd0-aa7f99090000 pid=2457 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=5bb698e2-1a00-0000-5cd0-aa7f99090000 pid=2457 clone guuid=cf91c5e2-1a00-0000-5cd0-aa7f9a090000 pid=2458 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=cf91c5e2-1a00-0000-5cd0-aa7f9a090000 pid=2458 clone guuid=f77cece2-1a00-0000-5cd0-aa7f9b090000 pid=2459 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=f77cece2-1a00-0000-5cd0-aa7f9b090000 pid=2459 clone guuid=142e12e3-1a00-0000-5cd0-aa7f9c090000 pid=2460 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=142e12e3-1a00-0000-5cd0-aa7f9c090000 pid=2460 clone guuid=10753fe3-1a00-0000-5cd0-aa7f9d090000 pid=2461 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=10753fe3-1a00-0000-5cd0-aa7f9d090000 pid=2461 clone guuid=097b61e3-1a00-0000-5cd0-aa7f9e090000 pid=2462 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=097b61e3-1a00-0000-5cd0-aa7f9e090000 pid=2462 clone guuid=b52281e3-1a00-0000-5cd0-aa7f9f090000 pid=2463 /usr/bin/bash guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=b52281e3-1a00-0000-5cd0-aa7f9f090000 pid=2463 clone guuid=4c3deee3-1a00-0000-5cd0-aa7fa0090000 pid=2464 /usr/bin/whoami guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=4c3deee3-1a00-0000-5cd0-aa7fa0090000 pid=2464 execve guuid=b10b4fe4-1a00-0000-5cd0-aa7fa1090000 pid=2465 /usr/bin/rm delete-file guuid=1351ebbd-1a00-0000-5cd0-aa7f60090000 pid=2400->guuid=b10b4fe4-1a00-0000-5cd0-aa7fa1090000 pid=2465 execve guuid=497e93bf-1a00-0000-5cd0-aa7f64090000 pid=2404 /usr/bin/dirname guuid=cf9e3fbf-1a00-0000-5cd0-aa7f62090000 pid=2402->guuid=497e93bf-1a00-0000-5cd0-aa7f64090000 pid=2404 execve guuid=636266c0-1a00-0000-5cd0-aa7f67090000 pid=2407 /usr/bin/whoami guuid=345942c0-1a00-0000-5cd0-aa7f66090000 pid=2406->guuid=636266c0-1a00-0000-5cd0-aa7f67090000 pid=2407 execve guuid=42c66cc0-1a00-0000-5cd0-aa7f68090000 pid=2408 /usr/bin/sed guuid=345942c0-1a00-0000-5cd0-aa7f66090000 pid=2406->guuid=42c66cc0-1a00-0000-5cd0-aa7f68090000 pid=2408 execve guuid=a92068c1-1a00-0000-5cd0-aa7f6c090000 pid=2412 /usr/bin/whoami guuid=73315cc1-1a00-0000-5cd0-aa7f6b090000 pid=2411->guuid=a92068c1-1a00-0000-5cd0-aa7f6c090000 pid=2412 execve guuid=36ac6ec1-1a00-0000-5cd0-aa7f6d090000 pid=2413 /usr/bin/sed guuid=73315cc1-1a00-0000-5cd0-aa7f6b090000 pid=2411->guuid=36ac6ec1-1a00-0000-5cd0-aa7f6d090000 pid=2413 execve guuid=13064ac2-1a00-0000-5cd0-aa7f71090000 pid=2417 /usr/bin/hostname guuid=73393bc2-1a00-0000-5cd0-aa7f6f090000 pid=2415->guuid=13064ac2-1a00-0000-5cd0-aa7f71090000 pid=2417 execve guuid=b92f4fc2-1a00-0000-5cd0-aa7f72090000 pid=2418 /usr/bin/sed guuid=73393bc2-1a00-0000-5cd0-aa7f6f090000 pid=2415->guuid=b92f4fc2-1a00-0000-5cd0-aa7f72090000 pid=2418 execve guuid=32ae55c2-1a00-0000-5cd0-aa7f73090000 pid=2419 /usr/bin/sed guuid=73393bc2-1a00-0000-5cd0-aa7f6f090000 pid=2415->guuid=32ae55c2-1a00-0000-5cd0-aa7f73090000 pid=2419 execve guuid=21f58ec4-1a00-0000-5cd0-aa7f78090000 pid=2424 /usr/bin/bash guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=21f58ec4-1a00-0000-5cd0-aa7f78090000 pid=2424 clone guuid=4d92c0c4-1a00-0000-5cd0-aa7f79090000 pid=2425 /usr/bin/python3.11 guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=4d92c0c4-1a00-0000-5cd0-aa7f79090000 pid=2425 execve guuid=076a5fd5-1a00-0000-5cd0-aa7f93090000 pid=2451 /usr/bin/python3.11 guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=076a5fd5-1a00-0000-5cd0-aa7f93090000 pid=2451 execve guuid=9b1689dd-1a00-0000-5cd0-aa7f94090000 pid=2452 /usr/bin/bash guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=9b1689dd-1a00-0000-5cd0-aa7f94090000 pid=2452 clone guuid=2874a7dd-1a00-0000-5cd0-aa7f95090000 pid=2453 /usr/bin/uname guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=2874a7dd-1a00-0000-5cd0-aa7f95090000 pid=2453 execve guuid=7babf4dd-1a00-0000-5cd0-aa7f96090000 pid=2454 /usr/bin/python3.11 guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=7babf4dd-1a00-0000-5cd0-aa7f96090000 pid=2454 execve guuid=b2dd10e0-1a00-0000-5cd0-aa7f97090000 pid=2455 /usr/bin/python3.11 guuid=a35c39c4-1a00-0000-5cd0-aa7f76090000 pid=2422->guuid=b2dd10e0-1a00-0000-5cd0-aa7f97090000 pid=2455 execve
Threat name:
MacOS.Infostealer.Generic
Status:
Suspicious
First seen:
2026-07-18 03:48:05 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:INDICATOR_SUSPICIOUS_Binary_Embedded_Crypto_Wallet_Browser_Extension_IDs
Author:ditekSHen
Description:Detect binaries embedding considerable number of cryptocurrency wallet browser extension IDs.
Rule name:Macos_Infostealer_Wallets_8e469ea0
Author:Elastic Security
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:telebot_framework
Author:vietdx.mb
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments