MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8dc79c044f08ba417cbec8a4e50d71de29351e9a657121fcdad3f32041a74ff7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8dc79c044f08ba417cbec8a4e50d71de29351e9a657121fcdad3f32041a74ff7
SHA3-384 hash: 61da0b1a5de4603d16a4a9e62c50cc4cab7e9b8d1036d0a05439bcb001398722059c0f064902814337abb8b86c604933
SHA1 hash: 205a21bbc8eb07bd987b49716c8d7714e1fa016a
MD5 hash: e49dbcebf4ba87e706c83aa6374de649
humanhash: jupiter-utah-fruit-mars
File name:proxyv2.sh
Download: download sample
File size:2'532 bytes
First seen:2026-04-05 04:12:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:eNJn57KOnWhNRv/BCslwTvIRbz3QPvlId/IkKj4651dF8q3o6yvM18rC6oXFd:Cp0mWRv9lwBPNCwzjRXj8q3o6ee8rRkd
TLSH T19A51C7C17DA49AB06F4BC835157B371AF017128A2B432968B09B2049DBFC8D253BED72
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Gathering data
Verdict:
Adware
File Type:
Script
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=7a15afb0-1600-0000-221d-24e2490e0000 pid=3657 /usr/bin/sudo guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658 /tmp/sample.bin guuid=7a15afb0-1600-0000-221d-24e2490e0000 pid=3657->guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658 execve guuid=77be87b4-1600-0000-221d-24e24e0e0000 pid=3662 /usr/bin/nproc guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=77be87b4-1600-0000-221d-24e24e0e0000 pid=3662 execve guuid=241e87b5-1600-0000-221d-24e2520e0000 pid=3666 /usr/bin/bash guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=241e87b5-1600-0000-221d-24e2520e0000 pid=3666 clone guuid=e225b8b9-1600-0000-221d-24e25d0e0000 pid=3677 /usr/bin/nproc guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=e225b8b9-1600-0000-221d-24e25d0e0000 pid=3677 execve guuid=9d9c1dba-1600-0000-221d-24e25e0e0000 pid=3678 /usr/bin/hostname guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=9d9c1dba-1600-0000-221d-24e25e0e0000 pid=3678 execve guuid=4e476fba-1600-0000-221d-24e25f0e0000 pid=3679 /usr/bin/uname guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=4e476fba-1600-0000-221d-24e25f0e0000 pid=3679 execve guuid=fb9cccba-1600-0000-221d-24e2600e0000 pid=3680 /usr/bin/bash guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=fb9cccba-1600-0000-221d-24e2600e0000 pid=3680 clone guuid=9a33d7ba-1600-0000-221d-24e2610e0000 pid=3681 /usr/bin/grep guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=9a33d7ba-1600-0000-221d-24e2610e0000 pid=3681 execve guuid=b253e2ba-1600-0000-221d-24e2620e0000 pid=3682 /usr/bin/bash guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=b253e2ba-1600-0000-221d-24e2620e0000 pid=3682 clone guuid=d3fa60bb-1600-0000-221d-24e2630e0000 pid=3683 /usr/bin/mkdir guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=d3fa60bb-1600-0000-221d-24e2630e0000 pid=3683 execve guuid=e1ebdcbb-1600-0000-221d-24e2640e0000 pid=3684 /usr/bin/wget dns net send-data write-file guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=e1ebdcbb-1600-0000-221d-24e2640e0000 pid=3684 execve guuid=e5efe5bb-1600-0000-221d-24e2650e0000 pid=3685 /usr/bin/tar write-file guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=e5efe5bb-1600-0000-221d-24e2650e0000 pid=3685 execve guuid=055d38ed-1600-0000-221d-24e20d0f0000 pid=3853 /usr/bin/mv guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=055d38ed-1600-0000-221d-24e20d0f0000 pid=3853 execve guuid=ca1f95ed-1600-0000-221d-24e2110f0000 pid=3857 /usr/bin/chmod guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=ca1f95ed-1600-0000-221d-24e2110f0000 pid=3857 execve guuid=9c3fd6ed-1600-0000-221d-24e2130f0000 pid=3859 /usr/sbin/sysctl write-file guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=9c3fd6ed-1600-0000-221d-24e2130f0000 pid=3859 execve guuid=0b6d43cc-1800-0000-221d-24e271140000 pid=5233 /usr/bin/cat write-config guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=0b6d43cc-1800-0000-221d-24e271140000 pid=5233 execve guuid=3e71a4cc-1800-0000-221d-24e272140000 pid=5234 /usr/bin/systemctl guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=3e71a4cc-1800-0000-221d-24e272140000 pid=5234 execve guuid=76e4bef8-1800-0000-221d-24e292140000 pid=5266 /usr/bin/systemctl guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=76e4bef8-1800-0000-221d-24e292140000 pid=5266 execve guuid=45548c21-1900-0000-221d-24e2a7140000 pid=5287 /usr/bin/systemctl guuid=6a7f7db3-1600-0000-221d-24e24a0e0000 pid=3658->guuid=45548c21-1900-0000-221d-24e2a7140000 pid=5287 execve guuid=6d3396b5-1600-0000-221d-24e2530e0000 pid=3667 /usr/bin/lscpu guuid=241e87b5-1600-0000-221d-24e2520e0000 pid=3666->guuid=6d3396b5-1600-0000-221d-24e2530e0000 pid=3667 execve guuid=afd3a1b5-1600-0000-221d-24e2540e0000 pid=3668 /usr/bin/grep guuid=241e87b5-1600-0000-221d-24e2520e0000 pid=3666->guuid=afd3a1b5-1600-0000-221d-24e2540e0000 pid=3668 execve guuid=6802abb5-1600-0000-221d-24e2550e0000 pid=3669 /usr/bin/mawk guuid=241e87b5-1600-0000-221d-24e2520e0000 pid=3666->guuid=6802abb5-1600-0000-221d-24e2550e0000 pid=3669 execve guuid=d304b4b5-1600-0000-221d-24e2560e0000 pid=3670 /usr/bin/sed guuid=241e87b5-1600-0000-221d-24e2520e0000 pid=3666->guuid=d304b4b5-1600-0000-221d-24e2560e0000 pid=3670 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e1ebdcbb-1600-0000-221d-24e2640e0000 pid=3684->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=e1ebdcbb-1600-0000-221d-24e2640e0000 pid=3684->75aab096-419b-50ef-be46-7d76b6a90e4c send: 806B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=e1ebdcbb-1600-0000-221d-24e2640e0000 pid=3684->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=e1ebdcbb-1600-0000-221d-24e2640e0000 pid=3684->f0eebea5-e97d-507c-a771-59cac353877c send: 1654B guuid=509f56bc-1600-0000-221d-24e2660e0000 pid=3686 /usr/bin/tar guuid=e5efe5bb-1600-0000-221d-24e2650e0000 pid=3685->guuid=509f56bc-1600-0000-221d-24e2660e0000 pid=3686 clone guuid=011161bc-1600-0000-221d-24e2670e0000 pid=3687 /usr/bin/gzip guuid=509f56bc-1600-0000-221d-24e2660e0000 pid=3686->guuid=011161bc-1600-0000-221d-24e2670e0000 pid=3687 execve
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks system information (zLinux)
Creates/modifies Cron job
Modifies systemd
File and Directory Permissions Modification
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8dc79c044f08ba417cbec8a4e50d71de29351e9a657121fcdad3f32041a74ff7

(this sample)

  
Delivery method
Distributed via web download

Comments