🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e87155da96e3218cf26ff3d3f816c0735b4d833bd32fa39799e0cc6b510fbd7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7e87155da96e3218cf26ff3d3f816c0735b4d833bd32fa39799e0cc6b510fbd7
SHA3-384 hash: 2356e1a7a2f8be3d2d423ef23e9cb39112a3ee3d7bf04835967d40fec9a71f9fb451d775a86779ffc30ac90e0b7a48b7
SHA1 hash: 9423e22db4e589a61389e0ff3ddad2b026af4fcb
MD5 hash: 761c30662bfb51257387c6b58231c435
humanhash: helium-zebra-chicken-one
File name:r.sh
Download: download sample
File size:192 bytes
First seen:2026-09-29 16:53:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH4vABwE+ZTVQmcMGGKlEbXcuqvPKVYFWGWJAwd8KLIOvPa2QjB83HG4sYF+2TA:hxE+ZTkMhtAuYPKGiAwd8hMPa5j2th+b
TLSH T1BAC012A079105064EA1DC53C7A45162D2645142BC0352D75B5C3C671515C1C974CE260
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Unknown
File Type:
unix shell
First seen:
2026-09-29T14:14:00Z UTC
Last seen:
2026-09-30T02:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=1eafef2a-1900-0000-a57f-e8591c050000 pid=1308 /usr/bin/sudo guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312 /tmp/sample.bin guuid=1eafef2a-1900-0000-a57f-e8591c050000 pid=1308->guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312 execve guuid=09a1662e-1900-0000-a57f-e85921050000 pid=1313 /usr/bin/dash write-file guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312->guuid=09a1662e-1900-0000-a57f-e85921050000 pid=1313 clone guuid=04a3722e-1900-0000-a57f-e85922050000 pid=1314 /usr/bin/sleep guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312->guuid=04a3722e-1900-0000-a57f-e85922050000 pid=1314 execve guuid=14e737a6-1900-0000-a57f-e85906060000 pid=1542 /usr/bin/ps guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312->guuid=14e737a6-1900-0000-a57f-e85906060000 pid=1542 execve guuid=077064ac-1900-0000-a57f-e85914060000 pid=1556 /usr/bin/cat guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312->guuid=077064ac-1900-0000-a57f-e85914060000 pid=1556 execve guuid=2467d1ac-1900-0000-a57f-e85916060000 pid=1558 /usr/bin/cat guuid=95e5ec2d-1900-0000-a57f-e85920050000 pid=1312->guuid=2467d1ac-1900-0000-a57f-e85916060000 pid=1558 execve
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Reads CPU attributes
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments