🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81fec51e2bca1049d24aa44edef067a07a08b8c3a5f32e504a958e75cfa6ea75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 81fec51e2bca1049d24aa44edef067a07a08b8c3a5f32e504a958e75cfa6ea75
SHA3-384 hash: 383044efa384ae2669d6c0b0ed71866b4d5b1a2a3646817cd3a471487b85a786704ff3b8bce44a976a250fdcd785961b
SHA1 hash: b8f22ef39e8bb7942febd16857358a927952e0a9
MD5 hash: 93c9763a48d73ed55ab6477cf5cc7396
humanhash: burger-nine-carolina-spring
File name:cirqueira.sh_sparc.sh
Download: download sample
File size:204 bytes
First seen:2026-09-16 15:10:59 UTC
Last seen:2026-09-16 23:26:39 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:nDyMzAHb5eFrNRE9ijZAMGc1tMLGFHI9Ks8DR0:nDyDHb5eFvFQe+LGFHjNm
TLSH T1F9D023C825C55D215D28571C756070B0C11D48D1FCEB44F8C1030441E441F553E08D47
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.227:8080/bins/cirqueira.shn/an/aascii bash sh ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-16T12:50:00Z UTC
Last seen:
2026-09-16T14:57:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=186348db-1b00-0000-c666-c270540a0000 pid=2644 /usr/bin/sudo guuid=bb3ef0e0-1b00-0000-c666-c270580a0000 pid=2648 /tmp/sample.bin guuid=186348db-1b00-0000-c666-c270540a0000 pid=2644->guuid=bb3ef0e0-1b00-0000-c666-c270580a0000 pid=2648 execve guuid=d5feade1-1b00-0000-c666-c2705a0a0000 pid=2650 /usr/bin/curl net guuid=bb3ef0e0-1b00-0000-c666-c270580a0000 pid=2648->guuid=d5feade1-1b00-0000-c666-c2705a0a0000 pid=2650 execve guuid=a29cbbe1-1b00-0000-c666-c2705b0a0000 pid=2651 /usr/bin/bash guuid=bb3ef0e0-1b00-0000-c666-c270580a0000 pid=2648->guuid=a29cbbe1-1b00-0000-c666-c2705b0a0000 pid=2651 execve fe26f427-538c-5707-ac13-a31600d7b93f 94.154.43.227:8080 guuid=d5feade1-1b00-0000-c666-c2705a0a0000 pid=2650->fe26f427-538c-5707-ac13-a31600d7b93f con
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 81fec51e2bca1049d24aa44edef067a07a08b8c3a5f32e504a958e75cfa6ea75

(this sample)

  
Delivery method
Distributed via web download

Comments