MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9135685a26d5517c154c17e4b8750f2cca02f06fbb5da620f3c520d4e313cc95. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 9135685a26d5517c154c17e4b8750f2cca02f06fbb5da620f3c520d4e313cc95
SHA3-384 hash: 0bae18abca8d80d74e672c4c40d27b33387fdb3666ba896ca03afc981c09924521e68580538fd89cdb7856e6a1742278
SHA1 hash: 1c822278f81525e5300a1854b0b90dd3f7677380
MD5 hash: 73fce6d34602b7e5c7be0ba0b4c894b3
humanhash: fix-fillet-earth-johnny
File name:9135685a26d5517c154c17e4b8750f2cca02f06fbb5da620f3c520d4e313cc95
Download: download sample
File size:1'584 bytes
First seen:2026-07-24 00:00:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UbNi6bNhLkk72dc6+hmYwoDN/6NdPlJV6Jq9b96l7i6l7VB7O5DII6IfFtLo9nb7:IzRl2CmjwjrXfYfFloGpbm9H0lLly8xA
TLSH T136314DDF44141A395613CADE73B33688A51C85FB289BDF94EC480EEE81495DC72A6FD0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:cowrie hermes-noc honeypot sh


Avatar
Anonymous
Captured by Hermes-NOC Cowrie SSH honeypot
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/921aban/an/aua-wget
http://5.182.210.61/2397cdn/an/aua-wget
http://5.182.210.61/db9a65n/an/aua-wget
http://5.182.210.61/479e00n/an/aua-wget
http://5.182.210.61/8fc4a8n/an/aua-wget
http://5.182.210.61/c9aac4n/an/aua-wget
http://5.182.210.61/6e3cddn/an/aua-wget
http://5.182.210.61/0a2607n/an/aua-wget
http://5.182.210.61/ff249fn/an/aua-wget
http://5.182.210.61/616a18n/an/aua-wget
http://5.182.210.61/16a477n/an/aua-wget
http://5.182.210.61/1caa7dn/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive mirai
Status:
terminated
Behavior Graph:
%3 guuid=60b0a9b5-1d00-0000-7a3d-8f99e0130000 pid=5088 /usr/bin/sudo guuid=8fd442b7-1d00-0000-7a3d-8f99e1130000 pid=5089 /tmp/sample.bin guuid=60b0a9b5-1d00-0000-7a3d-8f99e0130000 pid=5088->guuid=8fd442b7-1d00-0000-7a3d-8f99e1130000 pid=5089 execve guuid=41e29eb7-1d00-0000-7a3d-8f99e2130000 pid=5090 /usr/bin/wget guuid=8fd442b7-1d00-0000-7a3d-8f99e1130000 pid=5089->guuid=41e29eb7-1d00-0000-7a3d-8f99e2130000 pid=5090 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-24 00:02:06 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments