MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7948d3c2d350fdde560231c5c9b40f6ff51f1547a5dedc2cc53b59db9792b0c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7948d3c2d350fdde560231c5c9b40f6ff51f1547a5dedc2cc53b59db9792b0c7
SHA3-384 hash: 34e5ac87e02d2b6bd37ddd9a78f943079afa9d769df4db6994b90e81f01be2b2b670d839f3dd1004fc396d13c113c194
SHA1 hash: c5e675842dfe0f36241911abd245c8db69208162
MD5 hash: ee730424ae61b79066238ca2c7ae3c23
humanhash: magnesium-rugby-diet-autumn
File name:check.sh
Download: download sample
File size:847 bytes
First seen:2026-06-08 05:07:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:oEkDJFFHR1OuZU4CcxK9twF9Y4raEU6CRM1qvT4cDjhEgOk4Moq1bo2Q:oE+H1mBDMK9CF9YhEUXMM/hE4H1b2
TLSH T1C601ABDAA2206D303D8981AE33E7845C5242015F08CB7FD0BCCD64A01F1C548B051B39
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://91.224.92.34/check.shn/an/aelf ua-wget
http://91.224.92.34/syst3mdn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-08T02:11:00Z UTC
Last seen:
2026-06-08T12:59:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cw
Status:
terminated
Behavior Graph:
%3 guuid=ef9dca8c-1800-0000-5b43-3c70170d0000 pid=3351 /usr/bin/sudo guuid=ddd64c8e-1800-0000-5b43-3c701d0d0000 pid=3357 /tmp/sample.bin guuid=ef9dca8c-1800-0000-5b43-3c70170d0000 pid=3351->guuid=ddd64c8e-1800-0000-5b43-3c701d0d0000 pid=3357 execve guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359 /usr/bin/bash guuid=ddd64c8e-1800-0000-5b43-3c701d0d0000 pid=3357->guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359 clone guuid=996dae8e-1800-0000-5b43-3c70200d0000 pid=3360 /usr/bin/bash guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359->guuid=996dae8e-1800-0000-5b43-3c70200d0000 pid=3360 clone guuid=a9b5b58e-1800-0000-5b43-3c70210d0000 pid=3361 /usr/bin/grep guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359->guuid=a9b5b58e-1800-0000-5b43-3c70210d0000 pid=3361 execve guuid=3c6c148f-1800-0000-5b43-3c70230d0000 pid=3363 /usr/bin/bash guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359->guuid=3c6c148f-1800-0000-5b43-3c70230d0000 pid=3363 clone guuid=bd051e8f-1800-0000-5b43-3c70240d0000 pid=3364 /usr/bin/bash guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359->guuid=bd051e8f-1800-0000-5b43-3c70240d0000 pid=3364 clone guuid=da82508f-1800-0000-5b43-3c70260d0000 pid=3366 /usr/bin/pgrep guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359->guuid=da82508f-1800-0000-5b43-3c70260d0000 pid=3366 execve guuid=e4911f94-1800-0000-5b43-3c70310d0000 pid=3377 /usr/bin/curl net guuid=cba39d8e-1800-0000-5b43-3c701f0d0000 pid=3359->guuid=e4911f94-1800-0000-5b43-3c70310d0000 pid=3377 execve guuid=0a09278f-1800-0000-5b43-3c70250d0000 pid=3365 /usr/bin/bash guuid=3c6c148f-1800-0000-5b43-3c70230d0000 pid=3363->guuid=0a09278f-1800-0000-5b43-3c70250d0000 pid=3365 clone de98ceb8-6cef-586a-b951-fba9a5c33e33 91.224.92.34:80 guuid=e4911f94-1800-0000-5b43-3c70310d0000 pid=3377->de98ceb8-6cef-586a-b951-fba9a5c33e33 con
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-08 05:07:45 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7948d3c2d350fdde560231c5c9b40f6ff51f1547a5dedc2cc53b59db9792b0c7

(this sample)

  
Delivery method
Distributed via web download

Comments