🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 986d58b49ff1f942428bb1dad210bce36345d716fa90e9ed6c80b01d34657fea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 986d58b49ff1f942428bb1dad210bce36345d716fa90e9ed6c80b01d34657fea
SHA3-384 hash: 7e4f19f039c3f837472b48e38ab56041c5f1d0a28ebea15e2cc30d65f0ad94b54518802a737a895a4aa602c54b97435e
SHA1 hash: 7949c8618bdb3f1ab9f080a42ae5e0c0912e9f87
MD5 hash: 8585e0dfa50afa21f93f58f20b518459
humanhash: social-enemy-michigan-maryland
File name:cirqueira.sh_arc.sh
Download: download sample
File size:202 bytes
First seen:2026-09-16 15:10:58 UTC
Last seen:2026-09-16 16:12:46 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:nDyMzAHxNRE9ijZAMGc1tMLGFHI9Ks8DR0:nDyDHlFQe+LGFHjNm
TLSH T131D022CC3AC5AE215E285B2CB86060B0C11D88D2FCEB80F8C1030802E482F887E18A87
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.227:8080/bins/cirqueira.shn/an/aascii bash sh ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-16T12:50:00Z UTC
Last seen:
2026-09-16T14:57:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=001e4c83-1c00-0000-0d88-0d959e0a0000 pid=2718 /usr/bin/sudo guuid=aa28cc8a-1c00-0000-0d88-0d95a60a0000 pid=2726 /tmp/sample.bin guuid=001e4c83-1c00-0000-0d88-0d959e0a0000 pid=2718->guuid=aa28cc8a-1c00-0000-0d88-0d95a60a0000 pid=2726 execve guuid=8e5d698b-1c00-0000-0d88-0d95a80a0000 pid=2728 /usr/bin/curl net guuid=aa28cc8a-1c00-0000-0d88-0d95a60a0000 pid=2726->guuid=8e5d698b-1c00-0000-0d88-0d95a80a0000 pid=2728 execve guuid=a504738b-1c00-0000-0d88-0d95a90a0000 pid=2729 /usr/bin/bash guuid=aa28cc8a-1c00-0000-0d88-0d95a60a0000 pid=2726->guuid=a504738b-1c00-0000-0d88-0d95a90a0000 pid=2729 execve fe26f427-538c-5707-ac13-a31600d7b93f 94.154.43.227:8080 guuid=8e5d698b-1c00-0000-0d88-0d95a80a0000 pid=2728->fe26f427-538c-5707-ac13-a31600d7b93f con
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-09-16 15:11:34 UTC
File Type:
Text (Shell)
AV detection:
7 of 38 (18.42%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 986d58b49ff1f942428bb1dad210bce36345d716fa90e9ed6c80b01d34657fea

(this sample)

  
Delivery method
Distributed via web download

Comments