MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b9ba2f52c6346eec1f443e7a096175d57dcae5ac133e6050b1ca704c2da6ecf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9b9ba2f52c6346eec1f443e7a096175d57dcae5ac133e6050b1ca704c2da6ecf
SHA3-384 hash: c91ef5bf47990931fa3d0e571752ec3ac6b89ad7dc9bf7e3bed517c6b29ab86e3ca5c8e6fa963f68c36d3718c50430b5
SHA1 hash: f91d777f8e2ab0a542134c15250e7de439cd05ef
MD5 hash: c0601ca4ad7a1e0acf7bb8f15c3e414a
humanhash: pizza-victor-jupiter-august
File name:payload.sh
Download: download sample
File size:142 bytes
First seen:2026-08-09 01:17:37 UTC
Last seen:2026-08-09 14:17:29 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 3:TKH4vGBwOnQzVQNKKhC8pnhFMv7nhFMv1HK48aOSLK4FLV2:h96YKdph87h8NOa9Kb
TLSH T1B0C08C9C01A91C237A22C813501184303266BDC095C4AB24E6CDA932428CE003021383
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://217.60.195.143/botn/an/aua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-08T23:44:00Z UTC
Last seen:
2026-08-09T00:37:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=80c900ff-1700-0000-a66f-f0780e0a0000 pid=2574 /usr/bin/sudo guuid=824aa501-1800-0000-a66f-f078160a0000 pid=2582 /tmp/sample.bin guuid=80c900ff-1700-0000-a66f-f0780e0a0000 pid=2574->guuid=824aa501-1800-0000-a66f-f078160a0000 pid=2582 execve guuid=716fee01-1800-0000-a66f-f078170a0000 pid=2583 /usr/bin/wget net send-data write-file guuid=824aa501-1800-0000-a66f-f078160a0000 pid=2582->guuid=716fee01-1800-0000-a66f-f078170a0000 pid=2583 execve guuid=85e3fd0a-1800-0000-a66f-f0782e0a0000 pid=2606 /usr/bin/chmod guuid=824aa501-1800-0000-a66f-f078160a0000 pid=2582->guuid=85e3fd0a-1800-0000-a66f-f0782e0a0000 pid=2606 execve guuid=91bab90b-1800-0000-a66f-f078320a0000 pid=2610 /tmp/bot guuid=824aa501-1800-0000-a66f-f078160a0000 pid=2582->guuid=91bab90b-1800-0000-a66f-f078320a0000 pid=2610 execve 19347be6-e4a1-5ef2-be75-814cba901b71 217.60.195.143:80 guuid=716fee01-1800-0000-a66f-f078170a0000 pid=2583->19347be6-e4a1-5ef2-be75-814cba901b71 send: 132B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-09 01:18:42 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9b9ba2f52c6346eec1f443e7a096175d57dcae5ac133e6050b1ca704c2da6ecf

(this sample)

  
Delivery method
Distributed via web download

Comments