🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87cac5b8ac2e5e6b48ecc5ab5dc6c1c47b00fdbe2c12effd922a4a3e600bd55e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 87cac5b8ac2e5e6b48ecc5ab5dc6c1c47b00fdbe2c12effd922a4a3e600bd55e
SHA3-384 hash: 86b749b36c0f5a7f4e76040e49d37e8e00dad4cf48dbafc4512c02927f36cee019c9870be524828154fcc9139103491e
SHA1 hash: f458ae95e799bf5e14c2996a88a723fc63c982d0
MD5 hash: 3e1afc2ba443aa85c72a0e9f3134b85a
humanhash: may-glucose-berlin-connecticut
File name:.dcplm
Download: download sample
File size:10'944 bytes
First seen:2026-10-04 07:11:08 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:gOfkDnVNJDnJPM/Y4KpXEHOp1OBokIE2b5fAS9k:gXOY4KNEHaOkQ
TLSH T19332357370300E317FD80A6B6857680016A5586B061B7E58B5DC6479FF4B38CD3BAEAD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-29T09:27:00Z UTC
Last seen:
2026-04-30T21:00:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=46dfd1d7-1a00-0000-619e-967d74090000 pid=2420 /usr/bin/sudo guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426 /tmp/sample.bin write-file guuid=46dfd1d7-1a00-0000-619e-967d74090000 pid=2420->guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426 execve guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2428 /usr/bin/curl net send-data write-file guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2428 execve guuid=6b56a4de-1b00-0000-619e-967d230b0000 pid=2851 /usr/bin/rm delete-file guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=6b56a4de-1b00-0000-619e-967d230b0000 pid=2851 execve guuid=e498e5df-1b00-0000-619e-967d260b0000 pid=2854 /usr/bin/whoami guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=e498e5df-1b00-0000-619e-967d260b0000 pid=2854 execve guuid=6b5086e1-1b00-0000-619e-967d280b0000 pid=2856 /usr/bin/date guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=6b5086e1-1b00-0000-619e-967d280b0000 pid=2856 execve guuid=91d852e2-1b00-0000-619e-967d290b0000 pid=2857 /usr/bin/chattr guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=91d852e2-1b00-0000-619e-967d290b0000 pid=2857 execve guuid=bbc161e3-1b00-0000-619e-967d2b0b0000 pid=2859 /usr/bin/bash guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=bbc161e3-1b00-0000-619e-967d2b0b0000 pid=2859 clone guuid=275eaee3-1b00-0000-619e-967d2c0b0000 pid=2860 /usr/bin/mkdir guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=275eaee3-1b00-0000-619e-967d2c0b0000 pid=2860 execve guuid=da3bbbe4-1b00-0000-619e-967d2f0b0000 pid=2863 /usr/bin/id guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=da3bbbe4-1b00-0000-619e-967d2f0b0000 pid=2863 execve guuid=dadc44e6-1b00-0000-619e-967d320b0000 pid=2866 /usr/bin/sleep guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=dadc44e6-1b00-0000-619e-967d320b0000 pid=2866 execve guuid=14227b05-1c00-0000-619e-967d6b0b0000 pid=2923 /usr/bin/cat guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=14227b05-1c00-0000-619e-967d6b0b0000 pid=2923 execve guuid=fcf47e09-1c00-0000-619e-967d770b0000 pid=2935 /usr/bin/uname guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=fcf47e09-1c00-0000-619e-967d770b0000 pid=2935 execve guuid=a59ff909-1c00-0000-619e-967d790b0000 pid=2937 /usr/bin/wget guuid=3d4c00da-1a00-0000-619e-967d7a090000 pid=2426->guuid=a59ff909-1c00-0000-619e-967d790b0000 pid=2937 execve 95db98eb-9240-58c6-96b0-642f7e901c2e 0.0.0.4:80 guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2428->95db98eb-9240-58c6-96b0-642f7e901c2e con 1d928190-961a-5d8b-9877-fa3ff0ab3522 ifconfig.co:80 guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2428->1d928190-961a-5d8b-9877-fa3ff0ab3522 send: 75B guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2843 /usr/bin/curl dns net send-data guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2428->guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2843 clone guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2843->1d928190-961a-5d8b-9877-fa3ff0ab3522 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=b6e789da-1a00-0000-619e-967d7c090000 pid=2843->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 58B
Threat name:
Linux.Trojan.ShMiner
Status:
Malicious
First seen:
2026-01-29 14:22:14 UTC
File Type:
Text (Shell)
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Looks up external IP address via web service
Removes the immutable protection flag from a file
Write file to user bin folder
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dsc
Author:Aaron DeVera
Description:Discord domains
Rule name:LIN_Sample_Unique_586960df
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:586960df8bf559ffbba600f11917a99baed4a875cb7faa5eabc060bcde67277b.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 87cac5b8ac2e5e6b48ecc5ab5dc6c1c47b00fdbe2c12effd922a4a3e600bd55e

(this sample)

  
Delivery method
Distributed via web download

Comments