🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 865d0e0d689aa45461d13c5cdf6cd270f12d52112bdb20895e5bd47bfaf751bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 865d0e0d689aa45461d13c5cdf6cd270f12d52112bdb20895e5bd47bfaf751bd
SHA3-384 hash: 1fb2a6343f9bfa243fce59812e96ce9a6cd3c517daf2f6a3dd63cf42373cf036a987288a45160f804c728200ed6c3d97
SHA1 hash: 53eee43e569fd138539c2dd53e95c069fa343197
MD5 hash: 92c9dc3ddb4ba1002d81f4b27cd58d01
humanhash: ten-september-single-football
File name:bot.sh
Download: download sample
File size:4'340 bytes
First seen:2026-07-08 13:23:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:D1FBq9CK31dh+RBWEuK8lKt8Tzff8iVtRB:hFBmKtofV3B
TLSH T13991DD927C61B0B47E4B40294BBB6146340160479A253C3D36AF65160FEC7CA72EBEA7
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Adware
File Type:
unix shell
First seen:
2026-07-08T10:47:00Z UTC
Last seen:
2026-07-08T11:01:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c1431b6d-1900-0000-6497-b1d32e140000 pid=5166 /usr/bin/sudo guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167 /tmp/sample.bin guuid=c1431b6d-1900-0000-6497-b1d32e140000 pid=5166->guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167 execve guuid=d260d270-1900-0000-6497-b1d330140000 pid=5168 /usr/bin/uname guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=d260d270-1900-0000-6497-b1d330140000 pid=5168 execve guuid=906e3371-1900-0000-6497-b1d331140000 pid=5169 /usr/bin/uname guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=906e3371-1900-0000-6497-b1d331140000 pid=5169 execve guuid=fc73a271-1900-0000-6497-b1d332140000 pid=5170 /usr/bin/mkdir guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=fc73a271-1900-0000-6497-b1d332140000 pid=5170 execve guuid=08211d72-1900-0000-6497-b1d333140000 pid=5171 /usr/bin/bash guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=08211d72-1900-0000-6497-b1d333140000 pid=5171 clone guuid=17f98a9d-1900-0000-6497-b1d335140000 pid=5173 /usr/bin/bash guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=17f98a9d-1900-0000-6497-b1d335140000 pid=5173 clone guuid=8d68bca0-1900-0000-6497-b1d337140000 pid=5175 /usr/bin/bash guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=8d68bca0-1900-0000-6497-b1d337140000 pid=5175 clone guuid=8826b3a3-1900-0000-6497-b1d339140000 pid=5177 /usr/bin/bash guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=8826b3a3-1900-0000-6497-b1d339140000 pid=5177 clone guuid=54c790a6-1900-0000-6497-b1d33b140000 pid=5179 /usr/bin/bash guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=54c790a6-1900-0000-6497-b1d33b140000 pid=5179 clone guuid=2fa0c6a9-1900-0000-6497-b1d33d140000 pid=5181 /usr/bin/sleep guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=2fa0c6a9-1900-0000-6497-b1d33d140000 pid=5181 execve guuid=903207f1-1900-0000-6497-b1d33e140000 pid=5182 /usr/bin/wget net send-data guuid=26e05f70-1900-0000-6497-b1d32f140000 pid=5167->guuid=903207f1-1900-0000-6497-b1d33e140000 pid=5182 execve guuid=dbc83172-1900-0000-6497-b1d334140000 pid=5172 /usr/bin/pgrep guuid=08211d72-1900-0000-6497-b1d333140000 pid=5171->guuid=dbc83172-1900-0000-6497-b1d334140000 pid=5172 execve guuid=bd229c9d-1900-0000-6497-b1d336140000 pid=5174 /usr/bin/pgrep guuid=17f98a9d-1900-0000-6497-b1d335140000 pid=5173->guuid=bd229c9d-1900-0000-6497-b1d336140000 pid=5174 execve guuid=b8c8caa0-1900-0000-6497-b1d338140000 pid=5176 /usr/bin/pgrep guuid=8d68bca0-1900-0000-6497-b1d337140000 pid=5175->guuid=b8c8caa0-1900-0000-6497-b1d338140000 pid=5176 execve guuid=1bf2c0a3-1900-0000-6497-b1d33a140000 pid=5178 /usr/bin/pgrep guuid=8826b3a3-1900-0000-6497-b1d339140000 pid=5177->guuid=1bf2c0a3-1900-0000-6497-b1d33a140000 pid=5178 execve guuid=a1a29fa6-1900-0000-6497-b1d33c140000 pid=5180 /usr/bin/pgrep guuid=54c790a6-1900-0000-6497-b1d33b140000 pid=5179->guuid=a1a29fa6-1900-0000-6497-b1d33c140000 pid=5180 execve fd6168d6-80e8-545d-8a1b-29d60d3353ea 5.175.192.197:80 guuid=903207f1-1900-0000-6497-b1d33e140000 pid=5182->fd6168d6-80e8-545d-8a1b-29d60d3353ea send: 135B
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Modifies systemd
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 865d0e0d689aa45461d13c5cdf6cd270f12d52112bdb20895e5bd47bfaf751bd

(this sample)

  
Delivery method
Distributed via web download

Comments