MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 754480814846bdaa2154de4995d848591aa7fda666bef3475f3b4cec6ef541e3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 754480814846bdaa2154de4995d848591aa7fda666bef3475f3b4cec6ef541e3
SHA3-384 hash: 1780b3e0c862e2d8db1b2d920e65289edc659dbbfa7ce8c65c1320d5b978ad01369f07a551de4db3806c7b8c815a23e4
SHA1 hash: f4312cb22ba8b9fff87400f950fd4615a557cb38
MD5 hash: 50648d57f9bcb8c18fe60dd000a7a0b6
humanhash: cold-sad-mike-yellow
File name:cat.sh
Download: download sample
File size:1'957 bytes
First seen:2026-01-28 16:11:20 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ZVNPdM5L7O1U4iI8N7zFf9cxXUo7putLZJUlXl:ZVNPdM5L7O1U4iI8ZzFf9cxXUsuxZJUb
TLSH T12A41C49E60BC0045E08ACE7175F34DCCE309D69B55B8023AFDD22D6BE099CCB352AA71
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=806c4b01-1b00-0000-5c16-1bef0b0b0000 pid=2827 /usr/bin/sudo guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835 /tmp/sample.bin guuid=806c4b01-1b00-0000-5c16-1bef0b0b0000 pid=2827->guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835 execve guuid=7dee9404-1b00-0000-5c16-1bef140b0000 pid=2836 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=7dee9404-1b00-0000-5c16-1bef140b0000 pid=2836 execve guuid=4829ec07-1b00-0000-5c16-1bef1c0b0000 pid=2844 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=4829ec07-1b00-0000-5c16-1bef1c0b0000 pid=2844 execve guuid=fdeb340f-1b00-0000-5c16-1bef290b0000 pid=2857 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=fdeb340f-1b00-0000-5c16-1bef290b0000 pid=2857 execve guuid=fa768d0f-1b00-0000-5c16-1bef2b0b0000 pid=2859 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=fa768d0f-1b00-0000-5c16-1bef2b0b0000 pid=2859 clone guuid=896e9d0f-1b00-0000-5c16-1bef2c0b0000 pid=2860 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=896e9d0f-1b00-0000-5c16-1bef2c0b0000 pid=2860 execve guuid=65017e10-1b00-0000-5c16-1bef2e0b0000 pid=2862 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=65017e10-1b00-0000-5c16-1bef2e0b0000 pid=2862 execve guuid=adefaf12-1b00-0000-5c16-1bef2f0b0000 pid=2863 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=adefaf12-1b00-0000-5c16-1bef2f0b0000 pid=2863 execve guuid=6fb8f712-1b00-0000-5c16-1bef300b0000 pid=2864 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=6fb8f712-1b00-0000-5c16-1bef300b0000 pid=2864 clone guuid=7a3f0913-1b00-0000-5c16-1bef310b0000 pid=2865 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=7a3f0913-1b00-0000-5c16-1bef310b0000 pid=2865 execve guuid=9cecc313-1b00-0000-5c16-1bef320b0000 pid=2866 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=9cecc313-1b00-0000-5c16-1bef320b0000 pid=2866 execve guuid=1a5d091a-1b00-0000-5c16-1bef3f0b0000 pid=2879 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=1a5d091a-1b00-0000-5c16-1bef3f0b0000 pid=2879 execve guuid=98cd881a-1b00-0000-5c16-1bef410b0000 pid=2881 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=98cd881a-1b00-0000-5c16-1bef410b0000 pid=2881 clone guuid=7c01991a-1b00-0000-5c16-1bef420b0000 pid=2882 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=7c01991a-1b00-0000-5c16-1bef420b0000 pid=2882 execve guuid=a72b821b-1b00-0000-5c16-1bef460b0000 pid=2886 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=a72b821b-1b00-0000-5c16-1bef460b0000 pid=2886 execve guuid=33cd481d-1b00-0000-5c16-1bef4b0b0000 pid=2891 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=33cd481d-1b00-0000-5c16-1bef4b0b0000 pid=2891 execve guuid=2e8ca51d-1b00-0000-5c16-1bef4d0b0000 pid=2893 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=2e8ca51d-1b00-0000-5c16-1bef4d0b0000 pid=2893 clone guuid=3902ba1d-1b00-0000-5c16-1bef4e0b0000 pid=2894 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=3902ba1d-1b00-0000-5c16-1bef4e0b0000 pid=2894 execve guuid=db75681e-1b00-0000-5c16-1bef510b0000 pid=2897 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=db75681e-1b00-0000-5c16-1bef510b0000 pid=2897 execve guuid=f1129920-1b00-0000-5c16-1bef590b0000 pid=2905 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=f1129920-1b00-0000-5c16-1bef590b0000 pid=2905 execve guuid=e053d520-1b00-0000-5c16-1bef5b0b0000 pid=2907 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=e053d520-1b00-0000-5c16-1bef5b0b0000 pid=2907 clone guuid=7eb6df20-1b00-0000-5c16-1bef5c0b0000 pid=2908 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=7eb6df20-1b00-0000-5c16-1bef5c0b0000 pid=2908 execve guuid=f8f2ca21-1b00-0000-5c16-1bef610b0000 pid=2913 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=f8f2ca21-1b00-0000-5c16-1bef610b0000 pid=2913 execve guuid=8b0ea023-1b00-0000-5c16-1bef690b0000 pid=2921 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=8b0ea023-1b00-0000-5c16-1bef690b0000 pid=2921 execve guuid=e0d4e223-1b00-0000-5c16-1bef6b0b0000 pid=2923 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=e0d4e223-1b00-0000-5c16-1bef6b0b0000 pid=2923 clone guuid=babdf523-1b00-0000-5c16-1bef6c0b0000 pid=2924 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=babdf523-1b00-0000-5c16-1bef6c0b0000 pid=2924 execve guuid=de6aa924-1b00-0000-5c16-1bef6e0b0000 pid=2926 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=de6aa924-1b00-0000-5c16-1bef6e0b0000 pid=2926 execve guuid=b4725f27-1b00-0000-5c16-1bef790b0000 pid=2937 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=b4725f27-1b00-0000-5c16-1bef790b0000 pid=2937 execve guuid=60fcc627-1b00-0000-5c16-1bef7a0b0000 pid=2938 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=60fcc627-1b00-0000-5c16-1bef7a0b0000 pid=2938 clone guuid=4bdce827-1b00-0000-5c16-1bef7c0b0000 pid=2940 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=4bdce827-1b00-0000-5c16-1bef7c0b0000 pid=2940 execve guuid=b9a40c29-1b00-0000-5c16-1bef800b0000 pid=2944 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=b9a40c29-1b00-0000-5c16-1bef800b0000 pid=2944 execve guuid=fa20ea2b-1b00-0000-5c16-1bef870b0000 pid=2951 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=fa20ea2b-1b00-0000-5c16-1bef870b0000 pid=2951 execve guuid=955e272c-1b00-0000-5c16-1bef890b0000 pid=2953 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=955e272c-1b00-0000-5c16-1bef890b0000 pid=2953 clone guuid=700b382c-1b00-0000-5c16-1bef8a0b0000 pid=2954 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=700b382c-1b00-0000-5c16-1bef8a0b0000 pid=2954 execve guuid=838fe02c-1b00-0000-5c16-1bef8d0b0000 pid=2957 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=838fe02c-1b00-0000-5c16-1bef8d0b0000 pid=2957 execve guuid=89e4ee2e-1b00-0000-5c16-1bef920b0000 pid=2962 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=89e4ee2e-1b00-0000-5c16-1bef920b0000 pid=2962 execve guuid=0e0c472f-1b00-0000-5c16-1bef930b0000 pid=2963 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=0e0c472f-1b00-0000-5c16-1bef930b0000 pid=2963 clone guuid=a0505a2f-1b00-0000-5c16-1bef940b0000 pid=2964 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=a0505a2f-1b00-0000-5c16-1bef940b0000 pid=2964 execve guuid=55cd7a30-1b00-0000-5c16-1bef950b0000 pid=2965 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=55cd7a30-1b00-0000-5c16-1bef950b0000 pid=2965 execve guuid=36f67533-1b00-0000-5c16-1bef970b0000 pid=2967 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=36f67533-1b00-0000-5c16-1bef970b0000 pid=2967 execve guuid=32baf533-1b00-0000-5c16-1bef980b0000 pid=2968 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=32baf533-1b00-0000-5c16-1bef980b0000 pid=2968 clone guuid=4ccd0e34-1b00-0000-5c16-1bef990b0000 pid=2969 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=4ccd0e34-1b00-0000-5c16-1bef990b0000 pid=2969 execve guuid=876a5a35-1b00-0000-5c16-1bef9c0b0000 pid=2972 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=876a5a35-1b00-0000-5c16-1bef9c0b0000 pid=2972 execve guuid=f26b7937-1b00-0000-5c16-1befa20b0000 pid=2978 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=f26b7937-1b00-0000-5c16-1befa20b0000 pid=2978 execve guuid=c1eace37-1b00-0000-5c16-1befa30b0000 pid=2979 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=c1eace37-1b00-0000-5c16-1befa30b0000 pid=2979 clone guuid=5292de37-1b00-0000-5c16-1befa40b0000 pid=2980 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=5292de37-1b00-0000-5c16-1befa40b0000 pid=2980 execve guuid=ba34e638-1b00-0000-5c16-1befa50b0000 pid=2981 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=ba34e638-1b00-0000-5c16-1befa50b0000 pid=2981 execve guuid=de52a73a-1b00-0000-5c16-1befaa0b0000 pid=2986 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=de52a73a-1b00-0000-5c16-1befaa0b0000 pid=2986 execve guuid=facee73a-1b00-0000-5c16-1befac0b0000 pid=2988 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=facee73a-1b00-0000-5c16-1befac0b0000 pid=2988 clone guuid=c571ef3a-1b00-0000-5c16-1befad0b0000 pid=2989 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=c571ef3a-1b00-0000-5c16-1befad0b0000 pid=2989 execve guuid=17b5063c-1b00-0000-5c16-1befb00b0000 pid=2992 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=17b5063c-1b00-0000-5c16-1befb00b0000 pid=2992 execve guuid=b2e19d3e-1b00-0000-5c16-1befb60b0000 pid=2998 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=b2e19d3e-1b00-0000-5c16-1befb60b0000 pid=2998 execve guuid=5e7bf13e-1b00-0000-5c16-1befb80b0000 pid=3000 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=5e7bf13e-1b00-0000-5c16-1befb80b0000 pid=3000 clone guuid=1c6ffc3e-1b00-0000-5c16-1befb90b0000 pid=3001 /usr/bin/wget guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=1c6ffc3e-1b00-0000-5c16-1befb90b0000 pid=3001 execve guuid=1330f13f-1b00-0000-5c16-1befbb0b0000 pid=3003 /usr/bin/curl guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=1330f13f-1b00-0000-5c16-1befbb0b0000 pid=3003 execve guuid=a2141642-1b00-0000-5c16-1befc00b0000 pid=3008 /usr/bin/chmod guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=a2141642-1b00-0000-5c16-1befc00b0000 pid=3008 execve guuid=3e1c8042-1b00-0000-5c16-1befc10b0000 pid=3009 /usr/bin/dash guuid=76cf6204-1b00-0000-5c16-1bef130b0000 pid=2835->guuid=3e1c8042-1b00-0000-5c16-1befc10b0000 pid=3009 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-01-28 16:05:29 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 754480814846bdaa2154de4995d848591aa7fda666bef3475f3b4cec6ef541e3

(this sample)

  
Delivery method
Distributed via web download

Comments