MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7585d7f6546005b245690d439772cdf84bc0578c9ebb9a27b710ad8572c733d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 7585d7f6546005b245690d439772cdf84bc0578c9ebb9a27b710ad8572c733d4
SHA3-384 hash: 690dc140982cb26ba08e91375b05686f6e7561a4fc1b50c6aef7e3046ed24f95aa227579b17ea0e85dfe5f60dd68871c
SHA1 hash: 5daa233a69e9c3a7b8a5e6e7acc528413696d2ba
MD5 hash: bd14e58e8c0249501ced010c846eb83e
humanhash: gee-potato-six-texas
File name:59bkcgkaij.sh
Download: download sample
File size:161 bytes
First seen:2025-10-10 06:42:57 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 3:WFBIx8sv3uy9Fb+dNMf70vCnlLdIjdymHgmQmk0QQHFxaFOd6HhC:/9vrbsMfyelZIjYpZnoxa0
TLSH T1AAC08CD2452CD0729A350A9EB2E6E5E8DD4288248BF17CA2D924844834240751C0F73C
Magika shell
Reporter juroots
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://6516d.shortagegout.com/App.binn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
amos
Status:
terminated
Behavior Graph:
%3 guuid=3f254fb6-1900-0000-c26d-6b28080d0000 pid=3336 /usr/bin/sudo guuid=2d7331b8-1900-0000-c26d-6b280e0d0000 pid=3342 /tmp/sample.bin guuid=3f254fb6-1900-0000-c26d-6b28080d0000 pid=3336->guuid=2d7331b8-1900-0000-c26d-6b280e0d0000 pid=3342 execve guuid=bc9262b8-1900-0000-c26d-6b28100d0000 pid=3344 /usr/bin/dash guuid=2d7331b8-1900-0000-c26d-6b280e0d0000 pid=3342->guuid=bc9262b8-1900-0000-c26d-6b28100d0000 pid=3344 execve guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3346 /usr/bin/curl net send-data guuid=bc9262b8-1900-0000-c26d-6b28100d0000 pid=3344->guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3346 execve guuid=9c5c33cb-1900-0000-c26d-6b28460d0000 pid=3398 /usr/bin/chmod guuid=bc9262b8-1900-0000-c26d-6b28100d0000 pid=3344->guuid=9c5c33cb-1900-0000-c26d-6b28460d0000 pid=3398 execve fcd0ea0d-783a-51c1-866a-025cfa0b428c 6516d.shortagegout.com:443 guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3346->fcd0ea0d-783a-51c1-866a-025cfa0b428c send: 788B guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3362 /usr/bin/curl dns net send-data guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3346->guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3362 clone guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3362->fcd0ea0d-783a-51c1-866a-025cfa0b428c con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=a23dc3b8-1900-0000-c26d-6b28120d0000 pid=3362->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 80B
Threat name:
Text.Browser.Amos
Status:
Malicious
First seen:
2025-09-30 21:56:42 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7585d7f6546005b245690d439772cdf84bc0578c9ebb9a27b710ad8572c733d4

(this sample)

  
Delivery method
Distributed via web download

Comments