MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a559ab8f2cc7f4c0c52fb78beeecdb9995227ffbd766f4ff8e82721fe7b4438. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 8a559ab8f2cc7f4c0c52fb78beeecdb9995227ffbd766f4ff8e82721fe7b4438
SHA3-384 hash: c70e0032941dbdda3478084ce872743263191e99d180dc62400aeba3f1d76802c17d7bdaa9c3ae3dea9f56e9924d09e0
SHA1 hash: 8a4020d121847778fc634095f5522e1b5e58adf4
MD5 hash: ee07f106d53c88cfe53c265c363f3967
humanhash: virginia-wolfram-wisconsin-violet
File name:bin.sh
Download: download sample
File size:321 bytes
First seen:2026-04-29 12:18:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hrC1OW4oZYLWfp87Ty76VyoK9q4WgBtNW+1jY7Ld+1jl57c/AqFUCSkn:ZCkceLWa7Ty76Vyowq9gnI+yLd+dwbFP
TLSH T11FE0204FC09A253516395103E311CF24300510125EF2BBBCC449E722C747014F391F75
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-29T09:26:00Z UTC
Last seen:
2026-04-29T23:51:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi
Status:
terminated
Behavior Graph:
%3 guuid=e18d8385-1600-0000-5b83-16846a0d0000 pid=3434 /usr/bin/sudo guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441 /tmp/sample.bin guuid=e18d8385-1600-0000-5b83-16846a0d0000 pid=3434->guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441 execve guuid=2aefc287-1600-0000-5b83-1684730d0000 pid=3443 /usr/bin/pgrep guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441->guuid=2aefc287-1600-0000-5b83-1684730d0000 pid=3443 execve guuid=7b26048c-1600-0000-5b83-1684810d0000 pid=3457 /usr/bin/pgrep guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441->guuid=7b26048c-1600-0000-5b83-1684810d0000 pid=3457 execve guuid=9290848e-1600-0000-5b83-16848c0d0000 pid=3468 /usr/bin/wget net send-data write-file guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441->guuid=9290848e-1600-0000-5b83-16848c0d0000 pid=3468 execve guuid=d2663d93-1600-0000-5b83-1684960d0000 pid=3478 /usr/bin/chmod guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441->guuid=d2663d93-1600-0000-5b83-1684960d0000 pid=3478 execve guuid=74959c93-1600-0000-5b83-1684970d0000 pid=3479 /home/sandbox/boatnet.x86 net send-data write-file guuid=2ebf5787-1600-0000-5b83-1684710d0000 pid=3441->guuid=74959c93-1600-0000-5b83-1684970d0000 pid=3479 execve 40222482-1938-51c0-88ea-dfe53a920fa8 176.65.139.69:80 guuid=9290848e-1600-0000-5b83-16848c0d0000 pid=3468->40222482-1938-51c0-88ea-dfe53a920fa8 send: 149B 7d99d389-2e26-5467-9b0e-2a350925f31e 176.65.139.69:123 guuid=74959c93-1600-0000-5b83-1684970d0000 pid=3479->7d99d389-2e26-5467-9b0e-2a350925f31e send: 1B
Threat name:
Win32.Trojan.MiraiB
Status:
Malicious
First seen:
2026-04-29 12:18:32 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads CPU attributes
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8a559ab8f2cc7f4c0c52fb78beeecdb9995227ffbd766f4ff8e82721fe7b4438

(this sample)

  
Delivery method
Distributed via web download

Comments