MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8db1b95bdb5d8aa6a0b2c2357df49e537bcafb65e15582884b2c2588c74963df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



JackSkid


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 8db1b95bdb5d8aa6a0b2c2357df49e537bcafb65e15582884b2c2588c74963df
SHA3-384 hash: 43b333944ef3d5ab31fc89c2e3af608251ac5091d0d7e2d1795900e0955f01e7dee031d422cc8bb901da675caa9750fe
SHA1 hash: c04a7a70a299fb1a1d05350bf12c30d220422710
MD5 hash: 6d0b7ff3be9c45d66b444e933b6919f7
humanhash: lactose-october-monkey-wisconsin
File name:stager.sh
Download: download sample
Signature JackSkid
File size:598 bytes
First seen:2026-07-26 07:33:22 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:9pcgaOWpcgaOxcgaONyFQcga7jv+aQCROLvmPjwvmGSpvmPjm:94OW4OwOy7jv+aQfbm8mGSZmC
TLSH T19BF0782122B10E702A4A096D15C37C46A11A1C443DF21DCA62ED386096CF8AEE3A38AE
Magika shell
Reporter deepfield
Tags:ddos elf.jackskid jackskid rctea sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=40785640-1b00-0000-e938-891749090000 pid=2377 /usr/bin/sudo guuid=205e2b44-1b00-0000-e938-891752090000 pid=2386 /tmp/sample.bin guuid=40785640-1b00-0000-e938-891749090000 pid=2377->guuid=205e2b44-1b00-0000-e938-891752090000 pid=2386 execve guuid=3f3e8d44-1b00-0000-e938-891753090000 pid=2387 /usr/bin/dash guuid=205e2b44-1b00-0000-e938-891752090000 pid=2386->guuid=3f3e8d44-1b00-0000-e938-891753090000 pid=2387 clone guuid=b98dc444-1b00-0000-e938-891754090000 pid=2388 /usr/bin/rm guuid=205e2b44-1b00-0000-e938-891752090000 pid=2386->guuid=b98dc444-1b00-0000-e938-891754090000 pid=2388 execve
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments