🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85ee6a49c511123c6a108cf6e6b3ba1c00b38d28af3d053a5146ca78fb8df3be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 85ee6a49c511123c6a108cf6e6b3ba1c00b38d28af3d053a5146ca78fb8df3be
SHA3-384 hash: 419b473f37b72b3b9aa2499acdab4a1c6db7b99be56e42ca612b70f721fb2b6063eccd2c584cd960c2f07905cd8c5893
SHA1 hash: 41443efdf4f70d8a169e53026b71c02651c5a800
MD5 hash: c223366cf2f6b899fd65416146a7b9f6
humanhash: potato-whiskey-robin-north
File name:mbupload-forkchfb.bin
Download: download sample
File size:114 bytes
First seen:2026-10-05 23:17:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH4vGBwkSDETLtWiL71u9GN3+GuVjLWgKoKWnQDFz:hBD6xXL7mGEjuXVDFz
TLSH T185B012E922761E80F02C5E0570D71C50FB87827595545765F8C44C3BCD48601F103F15
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter wristhulk
Tags:cowrie Downloader honeypot sh


Avatar
wristhulk
Captured by a Cowrie honeypot at an unknown time.
URLMalware sample (SHA256 hash)SignatureTags
http://45.196.97.80/milan.armv7ln/an/awraith

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-05T22:48:00Z UTC
Last seen:
2026-10-06T19:47:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d031139d-1a00-0000-9cbf-0cfa0e0b0000 pid=2830 /usr/bin/sudo guuid=afa2a09f-1a00-0000-9cbf-0cfa110b0000 pid=2833 /tmp/sample.bin guuid=d031139d-1a00-0000-9cbf-0cfa0e0b0000 pid=2830->guuid=afa2a09f-1a00-0000-9cbf-0cfa110b0000 pid=2833 execve guuid=7e60f59f-1a00-0000-9cbf-0cfa130b0000 pid=2835 /usr/bin/wget guuid=afa2a09f-1a00-0000-9cbf-0cfa110b0000 pid=2833->guuid=7e60f59f-1a00-0000-9cbf-0cfa130b0000 pid=2835 execve
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-01 09:52:54 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
linux
Behaviour
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 85ee6a49c511123c6a108cf6e6b3ba1c00b38d28af3d053a5146ca78fb8df3be

(this sample)

  
Delivery method
Distributed via web download

Comments