MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ff39072d8f7cdf6e8e67f2eb34cb2c69400daa3788a2f0deb9e3450c6de19eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8ff39072d8f7cdf6e8e67f2eb34cb2c69400daa3788a2f0deb9e3450c6de19eb
SHA3-384 hash: 0727b2306d1aadb73a31daba945e69703c8e6185c4602f45ceb5518c7160c8ca643f95baa6caff60a9bd7986535ed1ec
SHA1 hash: b546753a06d7798b3775107f0bbafec8fc4cdc4f
MD5 hash: 03c63fc64383f30f36131baa9c5736c4
humanhash: mike-steak-eleven-xray
File name:build.sh
Download: download sample
File size:8'210 bytes
First seen:2025-11-21 23:37:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:u2vwpKXg5YyHrZL+8H14TVk/3lKWBPjQDQyQXVQaiQBQYRQsQXXQBQEgMQQZL+8H:j4VKW3fULHSOyeLObNYswjS
TLSH T12002F6157086787F55835833B137321BF572E0B69F3211AE807F42418FAAAE1259B9BF
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a1fd4295-1600-0000-6e43-337a690d0000 pid=3433 /usr/bin/sudo guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440 /tmp/sample.bin guuid=a1fd4295-1600-0000-6e43-337a690d0000 pid=3433->guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440 execve guuid=b6ca7d98-1600-0000-6e43-337a730d0000 pid=3443 /usr/bin/rm guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b6ca7d98-1600-0000-6e43-337a730d0000 pid=3443 execve guuid=62f4d398-1600-0000-6e43-337a750d0000 pid=3445 /usr/bin/mkdir guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=62f4d398-1600-0000-6e43-337a750d0000 pid=3445 execve guuid=f31d7a99-1600-0000-6e43-337a780d0000 pid=3448 /usr/bin/rm guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=f31d7a99-1600-0000-6e43-337a780d0000 pid=3448 execve guuid=28e4bb99-1600-0000-6e43-337a7a0d0000 pid=3450 /usr/bin/rm guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=28e4bb99-1600-0000-6e43-337a7a0d0000 pid=3450 execve guuid=851e079a-1600-0000-6e43-337a7c0d0000 pid=3452 /usr/bin/mkdir guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=851e079a-1600-0000-6e43-337a7c0d0000 pid=3452 execve guuid=b6d85f9a-1600-0000-6e43-337a7e0d0000 pid=3454 /usr/bin/mkdir guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b6d85f9a-1600-0000-6e43-337a7e0d0000 pid=3454 execve guuid=d6f6b99a-1600-0000-6e43-337a800d0000 pid=3456 /usr/bin/mkdir guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=d6f6b99a-1600-0000-6e43-337a800d0000 pid=3456 execve guuid=4b51229b-1600-0000-6e43-337a820d0000 pid=3458 /usr/bin/mkdir guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=4b51229b-1600-0000-6e43-337a820d0000 pid=3458 execve guuid=b3ed819b-1600-0000-6e43-337a840d0000 pid=3460 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b3ed819b-1600-0000-6e43-337a840d0000 pid=3460 clone guuid=07a19b9b-1600-0000-6e43-337a850d0000 pid=3461 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=07a19b9b-1600-0000-6e43-337a850d0000 pid=3461 clone guuid=8760bc9b-1600-0000-6e43-337a870d0000 pid=3463 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=8760bc9b-1600-0000-6e43-337a870d0000 pid=3463 clone guuid=fe8af89b-1600-0000-6e43-337a880d0000 pid=3464 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=fe8af89b-1600-0000-6e43-337a880d0000 pid=3464 clone guuid=d6b2109c-1600-0000-6e43-337a8a0d0000 pid=3466 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=d6b2109c-1600-0000-6e43-337a8a0d0000 pid=3466 clone guuid=7765299c-1600-0000-6e43-337a8b0d0000 pid=3467 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=7765299c-1600-0000-6e43-337a8b0d0000 pid=3467 clone guuid=6b123f9c-1600-0000-6e43-337a8c0d0000 pid=3468 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=6b123f9c-1600-0000-6e43-337a8c0d0000 pid=3468 clone guuid=7ecd589c-1600-0000-6e43-337a8e0d0000 pid=3470 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=7ecd589c-1600-0000-6e43-337a8e0d0000 pid=3470 clone guuid=3a916e9c-1600-0000-6e43-337a8f0d0000 pid=3471 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=3a916e9c-1600-0000-6e43-337a8f0d0000 pid=3471 clone guuid=7de4879c-1600-0000-6e43-337a900d0000 pid=3472 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=7de4879c-1600-0000-6e43-337a900d0000 pid=3472 clone guuid=fdbba59c-1600-0000-6e43-337a920d0000 pid=3474 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=fdbba59c-1600-0000-6e43-337a920d0000 pid=3474 clone guuid=5e69be9c-1600-0000-6e43-337a930d0000 pid=3475 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=5e69be9c-1600-0000-6e43-337a930d0000 pid=3475 clone guuid=8d57e29c-1600-0000-6e43-337a950d0000 pid=3477 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=8d57e29c-1600-0000-6e43-337a950d0000 pid=3477 clone guuid=1b8f039d-1600-0000-6e43-337a960d0000 pid=3478 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=1b8f039d-1600-0000-6e43-337a960d0000 pid=3478 clone guuid=96812e9d-1600-0000-6e43-337a980d0000 pid=3480 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=96812e9d-1600-0000-6e43-337a980d0000 pid=3480 clone guuid=17ed509d-1600-0000-6e43-337a990d0000 pid=3481 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=17ed509d-1600-0000-6e43-337a990d0000 pid=3481 clone guuid=8e47799d-1600-0000-6e43-337a9b0d0000 pid=3483 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=8e47799d-1600-0000-6e43-337a9b0d0000 pid=3483 clone guuid=65559b9d-1600-0000-6e43-337a9c0d0000 pid=3484 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=65559b9d-1600-0000-6e43-337a9c0d0000 pid=3484 clone guuid=e4f4c79d-1600-0000-6e43-337a9d0d0000 pid=3485 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=e4f4c79d-1600-0000-6e43-337a9d0d0000 pid=3485 clone guuid=dd7cea9d-1600-0000-6e43-337a9f0d0000 pid=3487 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=dd7cea9d-1600-0000-6e43-337a9f0d0000 pid=3487 clone guuid=2c16099e-1600-0000-6e43-337aa00d0000 pid=3488 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=2c16099e-1600-0000-6e43-337aa00d0000 pid=3488 clone guuid=09282b9e-1600-0000-6e43-337aa20d0000 pid=3490 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=09282b9e-1600-0000-6e43-337aa20d0000 pid=3490 clone guuid=e17e499e-1600-0000-6e43-337aa30d0000 pid=3491 /usr/bin/cp guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=e17e499e-1600-0000-6e43-337aa30d0000 pid=3491 execve guuid=68d4b89e-1600-0000-6e43-337aa50d0000 pid=3493 /usr/bin/cp guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=68d4b89e-1600-0000-6e43-337aa50d0000 pid=3493 execve guuid=4f3d149f-1600-0000-6e43-337aa70d0000 pid=3495 /usr/bin/mv guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=4f3d149f-1600-0000-6e43-337aa70d0000 pid=3495 execve guuid=f870709f-1600-0000-6e43-337aaa0d0000 pid=3498 /usr/bin/rm guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=f870709f-1600-0000-6e43-337aaa0d0000 pid=3498 execve guuid=cf32ad9f-1600-0000-6e43-337aac0d0000 pid=3500 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=cf32ad9f-1600-0000-6e43-337aac0d0000 pid=3500 clone guuid=5b6ec89f-1600-0000-6e43-337aad0d0000 pid=3501 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=5b6ec89f-1600-0000-6e43-337aad0d0000 pid=3501 clone guuid=2e94e09f-1600-0000-6e43-337aaf0d0000 pid=3503 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=2e94e09f-1600-0000-6e43-337aaf0d0000 pid=3503 clone guuid=81d205a0-1600-0000-6e43-337ab00d0000 pid=3504 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=81d205a0-1600-0000-6e43-337ab00d0000 pid=3504 clone guuid=c5ec1fa0-1600-0000-6e43-337ab10d0000 pid=3505 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=c5ec1fa0-1600-0000-6e43-337ab10d0000 pid=3505 clone guuid=166b44a0-1600-0000-6e43-337ab30d0000 pid=3507 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=166b44a0-1600-0000-6e43-337ab30d0000 pid=3507 clone guuid=478659a0-1600-0000-6e43-337ab40d0000 pid=3508 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=478659a0-1600-0000-6e43-337ab40d0000 pid=3508 clone guuid=93a678a0-1600-0000-6e43-337ab50d0000 pid=3509 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=93a678a0-1600-0000-6e43-337ab50d0000 pid=3509 clone guuid=b48e8ea0-1600-0000-6e43-337ab70d0000 pid=3511 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b48e8ea0-1600-0000-6e43-337ab70d0000 pid=3511 clone guuid=b1d8a5a0-1600-0000-6e43-337ab80d0000 pid=3512 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b1d8a5a0-1600-0000-6e43-337ab80d0000 pid=3512 clone guuid=0ec4bda0-1600-0000-6e43-337ab90d0000 pid=3513 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=0ec4bda0-1600-0000-6e43-337ab90d0000 pid=3513 clone guuid=0d6bd5a0-1600-0000-6e43-337aba0d0000 pid=3514 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=0d6bd5a0-1600-0000-6e43-337aba0d0000 pid=3514 clone guuid=254bf1a0-1600-0000-6e43-337abc0d0000 pid=3516 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=254bf1a0-1600-0000-6e43-337abc0d0000 pid=3516 clone guuid=7c5e10a1-1600-0000-6e43-337abd0d0000 pid=3517 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=7c5e10a1-1600-0000-6e43-337abd0d0000 pid=3517 clone guuid=b6872ca1-1600-0000-6e43-337abf0d0000 pid=3519 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b6872ca1-1600-0000-6e43-337abf0d0000 pid=3519 clone guuid=73ce45a1-1600-0000-6e43-337ac00d0000 pid=3520 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=73ce45a1-1600-0000-6e43-337ac00d0000 pid=3520 clone guuid=aa3266a1-1600-0000-6e43-337ac10d0000 pid=3521 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=aa3266a1-1600-0000-6e43-337ac10d0000 pid=3521 clone guuid=b7677aa1-1600-0000-6e43-337ac30d0000 pid=3523 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=b7677aa1-1600-0000-6e43-337ac30d0000 pid=3523 clone guuid=880bc0a1-1600-0000-6e43-337ac50d0000 pid=3525 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=880bc0a1-1600-0000-6e43-337ac50d0000 pid=3525 clone guuid=cdadd7a1-1600-0000-6e43-337ac60d0000 pid=3526 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=cdadd7a1-1600-0000-6e43-337ac60d0000 pid=3526 clone guuid=00a4eea1-1600-0000-6e43-337ac70d0000 pid=3527 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=00a4eea1-1600-0000-6e43-337ac70d0000 pid=3527 clone guuid=60f904a2-1600-0000-6e43-337ac90d0000 pid=3529 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=60f904a2-1600-0000-6e43-337ac90d0000 pid=3529 clone guuid=dc5e21a2-1600-0000-6e43-337acd0d0000 pid=3533 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=dc5e21a2-1600-0000-6e43-337acd0d0000 pid=3533 clone guuid=831f35a2-1600-0000-6e43-337ace0d0000 pid=3534 /usr/bin/mv guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=831f35a2-1600-0000-6e43-337ace0d0000 pid=3534 execve guuid=fabda5a2-1600-0000-6e43-337acf0d0000 pid=3535 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=fabda5a2-1600-0000-6e43-337acf0d0000 pid=3535 clone guuid=d17fc2a2-1600-0000-6e43-337ad00d0000 pid=3536 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=d17fc2a2-1600-0000-6e43-337ad00d0000 pid=3536 clone guuid=e6efdaa2-1600-0000-6e43-337ad10d0000 pid=3537 /usr/bin/bash guuid=62387297-1600-0000-6e43-337a700d0000 pid=3440->guuid=e6efdaa2-1600-0000-6e43-337ad10d0000 pid=3537 clone
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2025-11-20 21:37:33 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8ff39072d8f7cdf6e8e67f2eb34cb2c69400daa3788a2f0deb9e3450c6de19eb

(this sample)

  
Delivery method
Distributed via web download

Comments