MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9c62ae7e69f2641908484452aecde7e2dde2ea4a5133521f13767f0afa338b8e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 9c62ae7e69f2641908484452aecde7e2dde2ea4a5133521f13767f0afa338b8e
SHA3-384 hash: 5d8177379d30785f2aa65c876206e710533da5a66f1472f1f6321ef77af0e07a14fdbda4f47778609cfa0442f10965c2
SHA1 hash: ca445484e635fdfcbf2bfef859ed67159a30ada8
MD5 hash: f4473954168eeeaa3445f7fd7aa36fe3
humanhash: six-december-pizza-tennis
File name:9c62ae7e69f2641908484452aecde7e2dde2ea4a5133521f13767f0afa338b8e
Download: download sample
File size:1'584 bytes
First seen:2026-07-24 00:01:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:btT6TqdrQRH2h6JkeFt+pKz27QhkTT6OL+ccqQ:bpciQN2h6JkemKzaVYqQ
TLSH T11331729E01105A362217CACEB7A33589B10C86FB2D9BD3D4D84C9FED52495CC7261FD9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:cowrie hermes-noc honeypot sh


Avatar
Anonymous
Captured by Hermes-NOC Cowrie SSH honeypot
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/3d9525n/an/aua-wget
http://5.182.210.61/de3b50n/an/aua-wget
http://5.182.210.61/b451e5n/an/aua-wget
http://5.182.210.61/9d94afn/an/aua-wget
http://5.182.210.61/1fde74n/an/aua-wget
http://5.182.210.61/c7510cn/an/aua-wget
http://5.182.210.61/67e5dcn/an/aua-wget
http://5.182.210.61/7d1894n/an/aua-wget
http://5.182.210.61/2c2a7cn/an/aua-wget
http://5.182.210.61/e71574n/an/aua-wget
http://5.182.210.61/4ac21fn/an/aua-wget
http://5.182.210.61/5a9313n/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-23T22:14:00Z UTC
Last seen:
2026-07-23T22:45:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=eb21e2d7-1800-0000-abc8-0978b9130000 pid=5049 /usr/bin/sudo guuid=2910a0da-1800-0000-abc8-0978ba130000 pid=5050 /tmp/sample.bin guuid=eb21e2d7-1800-0000-abc8-0978b9130000 pid=5049->guuid=2910a0da-1800-0000-abc8-0978ba130000 pid=5050 execve guuid=653c13dc-1800-0000-abc8-0978bb130000 pid=5051 /usr/bin/wget guuid=2910a0da-1800-0000-abc8-0978ba130000 pid=5050->guuid=653c13dc-1800-0000-abc8-0978bb130000 pid=5051 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-24 00:02:07 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments