🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83b36b3a80677d6ef4a165cbbc808b4889c76d194f976eab37a8dfe5c8eabae1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 83b36b3a80677d6ef4a165cbbc808b4889c76d194f976eab37a8dfe5c8eabae1
SHA3-384 hash: 578a01bedc0e4db14cc0ece48a3b46b22f27a38be52a7723a10aca49b16fb9a2a7f18ad17db33dd31a0ffbce251d452d
SHA1 hash: 28761d64d60ba0fabc09ad85f54a978ccbaa1da7
MD5 hash: 0d81e06af1f21c6d886c02849a8d115d
humanhash: muppet-alpha-coffee-tennis
File name:83b36b3a80677d6ef4a165cbbc808b4889c76d194f976eab37a8dfe5c8eabae1
Download: download sample
File size:697 bytes
First seen:2026-10-01 20:38:56 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:5/KSmF7MYbbeMfTfNFSML1NRMW5M1NGM25m2MpMMk6+MPgOMVsoN/MMm1MYiuhmY:5/KR7MYbSMfB0ML1rMW5M1NGM2rMpMM7
TLSH T1F801C2423492B0E3C18BEA39EF1FF1086522F083C530E944F45E69362F87225BAD6A50
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter spydisec
Tags:cowrie dropper honeypot sh


Avatar
spydisec
Captured by an SSH/Telnet honeypot (cowrie). Downloaded from http://45.207.157.28/backdoor.sh; attacker IP(s): 45.144.52.239; first seen 2026-10-01T20:17:10Z.

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-30T22:22:00Z UTC
Last seen:
2026-10-02T04:30:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b8a9e9d8-1600-0000-1d11-2037260d0000 pid=3366 /usr/bin/sudo guuid=ed2774db-1600-0000-1d11-2037270d0000 pid=3367 /tmp/sample.bin guuid=b8a9e9d8-1600-0000-1d11-2037260d0000 pid=3366->guuid=ed2774db-1600-0000-1d11-2037270d0000 pid=3367 execve guuid=825cf8db-1600-0000-1d11-2037280d0000 pid=3368 /usr/bin/uname guuid=ed2774db-1600-0000-1d11-2037270d0000 pid=3367->guuid=825cf8db-1600-0000-1d11-2037280d0000 pid=3368 execve guuid=040984dc-1600-0000-1d11-20372b0d0000 pid=3371 /usr/bin/wget net send-data write-file guuid=ed2774db-1600-0000-1d11-2037270d0000 pid=3367->guuid=040984dc-1600-0000-1d11-20372b0d0000 pid=3371 execve guuid=b2ad9de8-1600-0000-1d11-20373f0d0000 pid=3391 /usr/bin/chmod guuid=ed2774db-1600-0000-1d11-2037270d0000 pid=3367->guuid=b2ad9de8-1600-0000-1d11-20373f0d0000 pid=3391 execve guuid=2ff9ede8-1600-0000-1d11-2037400d0000 pid=3392 /usr/bin/dash guuid=ed2774db-1600-0000-1d11-2037270d0000 pid=3367->guuid=2ff9ede8-1600-0000-1d11-2037400d0000 pid=3392 clone 2b85a69e-fa2b-5b51-b841-a05373892993 85.192.48.80:8888 guuid=040984dc-1600-0000-1d11-20372b0d0000 pid=3371->2b85a69e-fa2b-5b51-b841-a05373892993 send: 142B guuid=438ef9e8-1600-0000-1d11-2037410d0000 pid=3393 /tmp/.s write-config write-file zombie guuid=2ff9ede8-1600-0000-1d11-2037400d0000 pid=3392->guuid=438ef9e8-1600-0000-1d11-2037410d0000 pid=3393 execve guuid=6abb64e9-1600-0000-1d11-2037420d0000 pid=3394 /usr/bin/dash guuid=438ef9e8-1600-0000-1d11-2037410d0000 pid=3393->guuid=6abb64e9-1600-0000-1d11-2037420d0000 pid=3394 execve guuid=c22e812b-1700-0000-1d11-2037d20d0000 pid=3538 /usr/bin/dash guuid=438ef9e8-1600-0000-1d11-2037410d0000 pid=3393->guuid=c22e812b-1700-0000-1d11-2037d20d0000 pid=3538 execve guuid=56bfe14d-1700-0000-1d11-20375d0e0000 pid=3677 /usr/bin/dash guuid=438ef9e8-1600-0000-1d11-2037410d0000 pid=3393->guuid=56bfe14d-1700-0000-1d11-20375d0e0000 pid=3677 execve guuid=83b796e9-1600-0000-1d11-2037430d0000 pid=3395 /usr/bin/systemctl guuid=6abb64e9-1600-0000-1d11-2037420d0000 pid=3394->guuid=83b796e9-1600-0000-1d11-2037430d0000 pid=3395 execve guuid=d4a3b82b-1700-0000-1d11-2037d30d0000 pid=3539 /usr/bin/systemctl guuid=c22e812b-1700-0000-1d11-2037d20d0000 pid=3538->guuid=d4a3b82b-1700-0000-1d11-2037d30d0000 pid=3539 execve guuid=8698064e-1700-0000-1d11-20375f0e0000 pid=3679 /usr/local/bin/stress_agent zombie guuid=56bfe14d-1700-0000-1d11-20375d0e0000 pid=3677->guuid=8698064e-1700-0000-1d11-20375f0e0000 pid=3679 execve guuid=f30a3b4e-1700-0000-1d11-2037600e0000 pid=3680 /usr/local/bin/stress_agent zombie guuid=8698064e-1700-0000-1d11-20375f0e0000 pid=3679->guuid=f30a3b4e-1700-0000-1d11-2037600e0000 pid=3680 clone guuid=fda2444e-1700-0000-1d11-2037620e0000 pid=3682 /usr/local/bin/stress_agent zombie guuid=f30a3b4e-1700-0000-1d11-2037600e0000 pid=3680->guuid=fda2444e-1700-0000-1d11-2037620e0000 pid=3682 clone guuid=49124a4e-1700-0000-1d11-2037630e0000 pid=3683 /usr/local/bin/stress_agent dns net send-data write-file guuid=fda2444e-1700-0000-1d11-2037620e0000 pid=3682->guuid=49124a4e-1700-0000-1d11-2037630e0000 pid=3683 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=49124a4e-1700-0000-1d11-2037630e0000 pid=3683->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 32B a33fd58b-d685-577a-abfc-bfb6412503f9 91.92.40.130:9999 guuid=49124a4e-1700-0000-1d11-2037630e0000 pid=3683->a33fd58b-d685-577a-abfc-bfb6412503f9 send: 35B 5d28098a-239f-5967-8da5-e336208ef286 ntp.aliyun.com:123 guuid=49124a4e-1700-0000-1d11-2037630e0000 pid=3683->5d28098a-239f-5967-8da5-e336208ef286 send: 48B
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 83b36b3a80677d6ef4a165cbbc808b4889c76d194f976eab37a8dfe5c8eabae1

(this sample)

  
Delivery method
Distributed via web download

Comments