🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 887cee8882a211aa262f950214ae561cbce8f400ef63a9d46d7583c6cfbeafef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 887cee8882a211aa262f950214ae561cbce8f400ef63a9d46d7583c6cfbeafef
SHA3-384 hash: eccadec768af3fe66f64770e23c8ec095141da86d43d08fb8217310010f5b2eb1b77f75a492ba5f3471aeccebd18788f
SHA1 hash: b0f5fb6e9e22b43603ddaf3be6920aaf8a9f367b
MD5 hash: 7b3245f758c57123dcff30875e6b7d0e
humanhash: arkansas-jupiter-fruit-juliet
File name:887cee8882a211aa262f950214ae561cbce8f400ef63a9d46d7583c6cfbeafef
Download: download sample
File size:957 bytes
First seen:2026-10-02 04:33:15 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:wmhOsFzkV8/Ref418tY3dGU2A1JZ1J+F9s1y:HOsVDGtx01JZ1JqOc
TLSH T1AC1197F57636A2B2B308ED3CAF99165D6BC629A31424B900902E4CBCD01C78F728E734
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter asandov
Tags:cowrie honeypot sh
URLMalware sample (SHA256 hash)SignatureTags
http://8.216.48.50/hn/an/an/a
http://8.216.48.50/s/l3.shn/an/aascii bash sh ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
9
Origin country :
JP JP
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-26T03:51:00Z UTC
Last seen:
2026-10-02T15:08:00Z UTC
Hits:
~10
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
cURL User-Agent
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Creates/modifies Cron job
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments