MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8cd37b3de2d4e175cde202ef3bd2c51ab1f48053c46701efa470a250ff300e5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8cd37b3de2d4e175cde202ef3bd2c51ab1f48053c46701efa470a250ff300e5a
SHA3-384 hash: fa6debd4f6dd61b6911f5d70dde530b3a0e082f0c02e07c0c079be6de115531c65e29c6a6f0e9cce872354ee82a99c39
SHA1 hash: c266e040d5fe129921af22d0e0df75eeb2d49482
MD5 hash: ff991b0932ec2910a1551808febb3801
humanhash: robin-white-tennessee-rugby
File name:8cd37b3de2d4e175cde202ef3bd2c51ab1f48053c46701efa470a250ff300e5a_from_78.27.235.70_redis_set.bin
Download: download sample
File size:930 bytes
First seen:2026-07-31 10:44:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Buu36Ow6o4u36Ow0o0Tor8Y+hLx1vc0BvBysfGxE:oum4ukb4YW1ETE
TLSH T1A411BAB1B628CA24B44C50AD6D0CA3B5ECDE583F1A07AD0155105D36CA4FF8DA12C63C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter nullblue67
Tags:hexstrike kill-rivals sh shell ssh-backdoor takeover

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
masquerade
Status:
terminated
Behavior Graph:
%3 guuid=32dd0ec8-1a00-0000-05a8-b71cdb0a0000 pid=2779 /usr/bin/sudo guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783 /tmp/sample.bin write-config write-file guuid=32dd0ec8-1a00-0000-05a8-b71cdb0a0000 pid=2779->guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783 execve guuid=ff6f8fce-1a00-0000-05a8-b71ce00a0000 pid=2784 /usr/bin/mkdir guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=ff6f8fce-1a00-0000-05a8-b71ce00a0000 pid=2784 execve guuid=383ef0cf-1a00-0000-05a8-b71ce20a0000 pid=2786 /usr/bin/chmod guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=383ef0cf-1a00-0000-05a8-b71ce20a0000 pid=2786 execve guuid=67317ad0-1a00-0000-05a8-b71ce40a0000 pid=2788 /usr/bin/chmod guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=67317ad0-1a00-0000-05a8-b71ce40a0000 pid=2788 execve guuid=0cd3fad0-1a00-0000-05a8-b71ce60a0000 pid=2790 /usr/bin/rm guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=0cd3fad0-1a00-0000-05a8-b71ce60a0000 pid=2790 execve guuid=b301e8d1-1a00-0000-05a8-b71ce80a0000 pid=2792 /usr/sbin/xtables-nft-multi guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=b301e8d1-1a00-0000-05a8-b71ce80a0000 pid=2792 execve guuid=6e098de9-1a00-0000-05a8-b71cf90a0000 pid=2809 /usr/sbin/xtables-nft-multi guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=6e098de9-1a00-0000-05a8-b71cf90a0000 pid=2809 execve guuid=9d293aea-1a00-0000-05a8-b71cfb0a0000 pid=2811 /usr/bin/touch guuid=2b73dbcd-1a00-0000-05a8-b71cdf0a0000 pid=2783->guuid=9d293aea-1a00-0000-05a8-b71cfb0a0000 pid=2811 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-31 10:45:51 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Modifies the /etc/hosts DNS resolution file
Adds new SSH keys
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments