MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99b90eb991342097eed26458ceabae185c87416b8e5bb807c4e598a395cc2c3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 99b90eb991342097eed26458ceabae185c87416b8e5bb807c4e598a395cc2c3c
SHA3-384 hash: e2db68fc869883eb72c4ec579d5fb35ad45574f0aec8ea53b7cf30385560138d0ce1b969633ae78f147743290905706e
SHA1 hash: 1a8491ee51343b70dd0d3e7a2016cc7d3709bfe4
MD5 hash: a4e39e6492b8f51cb9d1da4a275f7eb7
humanhash: maryland-stairway-nine-georgia
File name:bin.sh
Download: download sample
File size:452 bytes
First seen:2026-04-27 20:51:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:ZCk47Tyyy0yowq9Ov0GyVpoQGy76ULnI+yLd+JM+0RwbFUO:ZCk47Tyyy0ytq9Ov0GyVpoQ976ULI+cq
TLSH T14EF0A08AC4AD1D360A7D8A13A320EB6830151462ABF27BF8D585D7218B5B038B341F65
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-27T18:14:00Z UTC
Last seen:
2026-04-27T18:48:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=9218ee9c-2000-0000-6a56-7ceb67090000 pid=2407 /usr/bin/sudo guuid=52f5b69e-2000-0000-6a56-7ceb6e090000 pid=2414 /tmp/sample.bin guuid=9218ee9c-2000-0000-6a56-7ceb67090000 pid=2407->guuid=52f5b69e-2000-0000-6a56-7ceb6e090000 pid=2414 execve guuid=c48ef09e-2000-0000-6a56-7ceb70090000 pid=2416 /usr/bin/wget net send-data write-file guuid=52f5b69e-2000-0000-6a56-7ceb6e090000 pid=2414->guuid=c48ef09e-2000-0000-6a56-7ceb70090000 pid=2416 execve guuid=933ce5a2-2000-0000-6a56-7ceb7c090000 pid=2428 /usr/bin/chmod guuid=52f5b69e-2000-0000-6a56-7ceb6e090000 pid=2414->guuid=933ce5a2-2000-0000-6a56-7ceb7c090000 pid=2428 execve guuid=60d439a3-2000-0000-6a56-7ceb7d090000 pid=2429 /home/sandbox/boatnet.x86 net send-data guuid=52f5b69e-2000-0000-6a56-7ceb6e090000 pid=2414->guuid=60d439a3-2000-0000-6a56-7ceb7d090000 pid=2429 execve 40222482-1938-51c0-88ea-dfe53a920fa8 176.65.139.69:80 guuid=c48ef09e-2000-0000-6a56-7ceb70090000 pid=2416->40222482-1938-51c0-88ea-dfe53a920fa8 send: 149B 7d99d389-2e26-5467-9b0e-2a350925f31e 176.65.139.69:123 guuid=60d439a3-2000-0000-6a56-7ceb7d090000 pid=2429->7d99d389-2e26-5467-9b0e-2a350925f31e send: 1B
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2026-04-27 20:54:42 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 99b90eb991342097eed26458ceabae185c87416b8e5bb807c4e598a395cc2c3c

(this sample)

  
Delivery method
Distributed via web download

Comments