🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b6c856fde38e4228e9aeb8afc04ae7f95ff50e40e690f06963439cffc3cc5fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9b6c856fde38e4228e9aeb8afc04ae7f95ff50e40e690f06963439cffc3cc5fa
SHA3-384 hash: 101ee27f1c2b9d398075c86a6ef59c0e06b76a2ce3581fe83ae660f4af1e13c33c9c8f69ce556ce8b41a4a1b8fd261ca
SHA1 hash: e5820a63910a5ce42dc9e2adbb4bd50dd9215123
MD5 hash: 02c9f0f26de33f9c10a72b87a3b8a478
humanhash: eleven-helium-pizza-papa
File name:9b6c856fde38e4228e9aeb8afc04ae7f95ff50e40e690f06963439cffc3cc5fa.bin
Download: download sample
File size:536 bytes
First seen:2026-10-03 20:23:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:vFedZnsL0FNIJMyskjshmJFmDvIGS+FCqsA6jWRsPmqnQWlL:vFCZsL0FHysaskqvIGPsA6SsPmqn5L
TLSH T18BF024E0F51C19213937D6FE222948E48606987B1E603D4424C1E4B43FEF6B9B4C863A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter whack_sh
Tags:script sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Unknown
File Type:
unix shell
First seen:
2026-09-10T15:52:00Z UTC
Last seen:
2026-10-04T10:25:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2e817907-1a00-0000-a7e2-a4307e070000 pid=1918 /usr/bin/sudo guuid=9974ca09-1a00-0000-a7e2-a43085070000 pid=1925 /tmp/sample.bin guuid=2e817907-1a00-0000-a7e2-a4307e070000 pid=1918->guuid=9974ca09-1a00-0000-a7e2-a43085070000 pid=1925 execve guuid=5ee1630a-1a00-0000-a7e2-a43086070000 pid=1926 /usr/bin/dash guuid=9974ca09-1a00-0000-a7e2-a43085070000 pid=1925->guuid=5ee1630a-1a00-0000-a7e2-a43086070000 pid=1926 clone guuid=ef09bd0b-1a00-0000-a7e2-a4308a070000 pid=1930 /usr/bin/dash guuid=9974ca09-1a00-0000-a7e2-a43085070000 pid=1925->guuid=ef09bd0b-1a00-0000-a7e2-a4308a070000 pid=1930 clone guuid=ca918f0a-1a00-0000-a7e2-a43087070000 pid=1927 /usr/bin/cat guuid=5ee1630a-1a00-0000-a7e2-a43086070000 pid=1926->guuid=ca918f0a-1a00-0000-a7e2-a43087070000 pid=1927 execve guuid=72c3a20a-1a00-0000-a7e2-a43088070000 pid=1928 /usr/bin/cut guuid=5ee1630a-1a00-0000-a7e2-a43086070000 pid=1926->guuid=72c3a20a-1a00-0000-a7e2-a43088070000 pid=1928 execve guuid=6608d30b-1a00-0000-a7e2-a4308b070000 pid=1931 /usr/bin/sleep guuid=ef09bd0b-1a00-0000-a7e2-a4308a070000 pid=1930->guuid=6608d30b-1a00-0000-a7e2-a4308b070000 pid=1931 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-10 20:36:55 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9b6c856fde38e4228e9aeb8afc04ae7f95ff50e40e690f06963439cffc3cc5fa

(this sample)

  
Delivery method
Distributed via web download

Comments