MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92ab54d8ddfe5a408bb519d720fd58b0745c405991e41ec420f9132cdce57e2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 92ab54d8ddfe5a408bb519d720fd58b0745c405991e41ec420f9132cdce57e2f
SHA3-384 hash: e40f2e68436d2c2889da7991d85076a2cc519e6847271b2c8cebbea9496cb88bd30cab82413479cb96f3a7b5671c80cb
SHA1 hash: 14f37f31a9bffb48a78412b7f926b824222356bf
MD5 hash: cdd9932e575883489a546a455d9e06b5
humanhash: mirror-sierra-north-missouri
File name:updater
Download: download sample
File size:344 bytes
First seen:2026-04-01 05:51:06 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hoCeceeCgj+MIlR7DTFZTFWubxPEWDTrFMBeTP5pUnB0WgymDGp0DFz:McefS+F7DxZ4ux8WDXFMwnWd+GK
TLSH T17DE026409812E873910E0DA4C94DB26CAC9A6CCBA0029E0DE140FEF51C8FA0033ADFC0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
NL NL
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-01T06:52:00Z UTC
Last seen:
2026-04-02T18:48:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=bc35d9cb-2000-0000-3b8a-1930ec0a0000 pid=2796 /usr/bin/sudo guuid=8faa05ce-2000-0000-3b8a-1930f10a0000 pid=2801 /tmp/sample.bin guuid=bc35d9cb-2000-0000-3b8a-1930ec0a0000 pid=2796->guuid=8faa05ce-2000-0000-3b8a-1930f10a0000 pid=2801 execve guuid=b5b840ce-2000-0000-3b8a-1930f20a0000 pid=2802 /usr/bin/uname guuid=8faa05ce-2000-0000-3b8a-1930f10a0000 pid=2801->guuid=b5b840ce-2000-0000-3b8a-1930f20a0000 pid=2802 execve guuid=1325a6ce-2000-0000-3b8a-1930f40a0000 pid=2804 /usr/bin/curl net send-data write-file guuid=8faa05ce-2000-0000-3b8a-1930f10a0000 pid=2801->guuid=1325a6ce-2000-0000-3b8a-1930f40a0000 pid=2804 execve guuid=d7d25742-2100-0000-3b8a-1930b50b0000 pid=2997 /usr/bin/chmod guuid=8faa05ce-2000-0000-3b8a-1930f10a0000 pid=2801->guuid=d7d25742-2100-0000-3b8a-1930b50b0000 pid=2997 execve guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999 /tmp/.svc net write-config write-file zombie guuid=8faa05ce-2000-0000-3b8a-1930f10a0000 pid=2801->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999 execve d8be1f00-e1f2-500c-a4f5-abd0b972dd0d 103.79.79.21:8899 guuid=1325a6ce-2000-0000-3b8a-1930f40a0000 pid=2804->d8be1f00-e1f2-500c-a4f5-abd0b972dd0d send: 95B guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->d8be1f00-e1f2-500c-a4f5-abd0b972dd0d con 51475a40-5531-5652-88be-7dda12342b64 8.8.8.8:80 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->51475a40-5531-5652-88be-7dda12342b64 con a7bd1f4e-86b5-5576-ab86-4c3c647bed46 54.189.35.179:80 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->a7bd1f4e-86b5-5576-ab86-4c3c647bed46 con e450d780-34c9-5d14-bcf7-fa07e15459de 54.189.35.179:8080 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->e450d780-34c9-5d14-bcf7-fa07e15459de con acb6b93d-ba60-52ab-a022-4bdc94e68817 54.189.35.179:8443 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->acb6b93d-ba60-52ab-a022-4bdc94e68817 con b52553a6-3938-5b66-b4bb-59e96c287b05 51.20.92.94:8080 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->b52553a6-3938-5b66-b4bb-59e96c287b05 con ae2233df-49c6-553a-9662-b94df5d1e445 51.20.92.94:8888 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->ae2233df-49c6-553a-9662-b94df5d1e445 con f627ae33-8e44-5728-8a78-2d90412bb55f 103.79.79.21:4444 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->f627ae33-8e44-5728-8a78-2d90412bb55f con 7e37b0d7-e195-5109-8f9b-60c739e5f257 34.203.194.72:80 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->7e37b0d7-e195-5109-8f9b-60c739e5f257 con 70d3e9fb-38d3-5541-8ab6-ba902b667e92 34.203.194.72:8080 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->70d3e9fb-38d3-5541-8ab6-ba902b667e92 con guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3010 /tmp/.svc zombie guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3010 clone guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3011 /tmp/.svc net send-data zombie guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3011 clone guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3013 /tmp/.svc guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3013 clone guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014 /tmp/.svc net zombie guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014 clone guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3024 /tmp/.svc net send-data zombie guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3024 clone guuid=96bf8e4f-2100-0000-3b8a-1930d40b0000 pid=3028 /tmp/.svc guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=96bf8e4f-2100-0000-3b8a-1930d40b0000 pid=3028 clone guuid=5c98b84f-2100-0000-3b8a-1930d60b0000 pid=3030 /usr/bin/which.debianutils guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=5c98b84f-2100-0000-3b8a-1930d60b0000 pid=3030 execve guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=5278 /tmp/.svc net zombie guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=5278 clone guuid=b055c151-2800-0000-3b8a-1930a1140000 pid=5281 /usr/bin/systemctl guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=b055c151-2800-0000-3b8a-1930a1140000 pid=5281 execve guuid=5abdfd75-2800-0000-3b8a-1930b6140000 pid=5302 /usr/bin/systemctl guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=5abdfd75-2800-0000-3b8a-1930b6140000 pid=5302 execve guuid=a8c2cd95-2800-0000-3b8a-1930cb140000 pid=5323 /usr/bin/systemctl guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=2999->guuid=a8c2cd95-2800-0000-3b8a-1930cb140000 pid=5323 execve guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3011->d8be1f00-e1f2-500c-a4f5-abd0b972dd0d send: 345B ad17d1a6-60dd-5968-874f-b0ee96d6f647 54.189.35.179:443 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3011->ad17d1a6-60dd-5968-874f-b0ee96d6f647 con fcdd15aa-e412-5642-a6a3-2ca4b2d1da35 54.189.35.179:8888 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3011->fcdd15aa-e412-5642-a6a3-2ca4b2d1da35 con guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->f627ae33-8e44-5728-8a78-2d90412bb55f con dbd87688-ad1a-5df8-ada4-e70c7135e328 51.20.92.94:443 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->dbd87688-ad1a-5df8-ada4-e70c7135e328 con fc7302d8-b284-5768-9bce-dbab11cbcc3b 51.20.92.94:8443 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->fc7302d8-b284-5768-9bce-dbab11cbcc3b con 0515116d-a0b0-5a08-8099-f27f87ab3d6a 34.203.194.72:443 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->0515116d-a0b0-5a08-8099-f27f87ab3d6a con aa6d0b80-339a-5f6d-8424-3b60579a93d1 34.203.194.72:8443 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->aa6d0b80-339a-5f6d-8424-3b60579a93d1 con fb8d9c9b-19df-5226-8979-e74dd8b67b72 34.203.194.72:8888 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->fb8d9c9b-19df-5226-8979-e74dd8b67b72 con guuid=614abf50-2100-0000-3b8a-1930db0b0000 pid=3035 /usr/bin/which.debianutils guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->guuid=614abf50-2100-0000-3b8a-1930db0b0000 pid=3035 execve guuid=d0239a4d-2800-0000-3b8a-1930a0140000 pid=5280 /usr/bin/which.debianutils guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3014->guuid=d0239a4d-2800-0000-3b8a-1930a0140000 pid=5280 execve guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3024->d8be1f00-e1f2-500c-a4f5-abd0b972dd0d send: 107B guuid=97f53150-2100-0000-3b8a-1930d80b0000 pid=3032 /usr/bin/which.debianutils guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3024->guuid=97f53150-2100-0000-3b8a-1930d80b0000 pid=3032 execve guuid=8039f04b-2800-0000-3b8a-19309d140000 pid=5277 /usr/bin/which.debianutils guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3024->guuid=8039f04b-2800-0000-3b8a-19309d140000 pid=5277 execve guuid=a549534d-2800-0000-3b8a-19309f140000 pid=5279 /usr/bin/which.debianutils guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=3024->guuid=a549534d-2800-0000-3b8a-19309f140000 pid=5279 execve guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=5278->f627ae33-8e44-5728-8a78-2d90412bb55f con 6332e863-40e1-5b7d-8415-83d76bff68a3 51.20.92.94:80 guuid=14449c42-2100-0000-3b8a-1930b70b0000 pid=5278->6332e863-40e1-5b7d-8415-83d76bff68a3 con
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Creates/modifies Cron job
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments