MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8db103466c032c12d0b945bc1f86e62039f9b2f44779c7450eac9e52251fcd62. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8db103466c032c12d0b945bc1f86e62039f9b2f44779c7450eac9e52251fcd62
SHA3-384 hash: 2c59d85368ca0923ae2d0ee0a6cab3161b6f7eb7f6eb127eb1b7a27e88df8ce085d486414b2f892d261d99e7cc891bf2
SHA1 hash: 8c1ef8b59a877201b3a1dd6c14a19548afb93a72
MD5 hash: 131885f70f0da9c801643a77ec611c8e
humanhash: cola-south-edward-xray
File name:8db103466c032c12d0b945bc1f86e62039f9b2f44779c7450eac9e52251fcd62
Download: download sample
File size:7'114 bytes
First seen:2026-05-26 08:34:39 UTC
Last seen:2026-08-11 20:30:01 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:Wpf2n2Sg916x2xxMfNtg5uoqdfeqDWochsdy65:IHICEmudd2qDWoek3
TLSH T1E1E1849A1C6118F57B4FC8198E6B8115301F38172A026C24F5DDA4E96FECBB58373E76
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter hett
Tags:bash dropper honeypot linux proxyware script sh shardlure


Avatar
hett
Captured by ShardLure honeypot. Suspected family: Traffmonetizer. File kind: Shell script. Captured: 2026-05-22.

Intelligence


File Origin
# of uploads :
2
# of downloads :
97
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash lolbin obfuscated
Status:
terminated
Behavior Graph:
%3 guuid=caf24953-1800-0000-92ab-ec9c480a0000 pid=2632 /usr/bin/sudo guuid=f650ca55-1800-0000-92ab-ec9c4e0a0000 pid=2638 /tmp/sample.bin guuid=caf24953-1800-0000-92ab-ec9c480a0000 pid=2632->guuid=f650ca55-1800-0000-92ab-ec9c4e0a0000 pid=2638 execve
Threat name:
Linux.Trojan.SAgnt
Status:
Malicious
First seen:
2026-05-13 18:54:02 UTC
File Type:
Text (Shell)
AV detection:
4 of 23 (17.39%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments