🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78aba74a86285dfaa346eb470028b3af5cd5ad04de138e008a7d51b98927f0ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 78aba74a86285dfaa346eb470028b3af5cd5ad04de138e008a7d51b98927f0ee
SHA3-384 hash: b4ffe9691e1604288cbe3ef6f81082ab8c6c3c0c1e83357962d7a403932c53eaee2b9a0ba3f91b48dd1eb57b7b580152
SHA1 hash: b3abe63b122171a4512d2177741ac44dc3e7aaed
MD5 hash: 29c70803a5c63b5f8807d1f64503c474
humanhash: earth-louisiana-india-pip
File name:78aba74a86285dfaa346eb470028b3af5cd5ad04de138e008a7d51b98927f0ee
Download: download sample
File size:293 bytes
First seen:2026-09-09 14:11:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:UqLqhR47DcKULt1cK8MNIzuLIUSICMNIcK8MNQkYcK8MN25FTEX3:UquhRADEt1VBILIQVIVsQ
TLSH T1BFE0C240E6A13E142675EE0E83D4930E523057F0F95C7A7D99DAC7F60A644C3348EF99
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.146.27.178/302/tokenlinux.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
20
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
bash lolbin
Status:
terminated
Behavior Graph:
%3 guuid=ee8dcda2-1900-0000-4e7f-29c8a10a0000 pid=2721 /usr/bin/sudo guuid=383fd7a4-1900-0000-4e7f-29c8a30a0000 pid=2723 /tmp/sample.bin guuid=ee8dcda2-1900-0000-4e7f-29c8a10a0000 pid=2721->guuid=383fd7a4-1900-0000-4e7f-29c8a30a0000 pid=2723 execve guuid=bc4071a5-1900-0000-4e7f-29c8a50a0000 pid=2725 /usr/bin/mkdir guuid=383fd7a4-1900-0000-4e7f-29c8a30a0000 pid=2723->guuid=bc4071a5-1900-0000-4e7f-29c8a50a0000 pid=2725 execve guuid=be4ffaa5-1900-0000-4e7f-29c8a80a0000 pid=2728 /usr/bin/clear guuid=383fd7a4-1900-0000-4e7f-29c8a30a0000 pid=2723->guuid=be4ffaa5-1900-0000-4e7f-29c8a80a0000 pid=2728 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments