MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e25f21a0eaff4358a3125a60b006b67369370bcaa62a96b033c2bfa445fef35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9e25f21a0eaff4358a3125a60b006b67369370bcaa62a96b033c2bfa445fef35
SHA3-384 hash: 66d8455dcf2bbb5c80e909a118a8a7d607fa11b0cd0ddbc91ff64191cadb61820746d0eb65b06e28e36728f9fa1eafef
SHA1 hash: 742bfeb129055e2b167fecc5373e0e26fc30ba39
MD5 hash: 4ecad6fb60ce98efb36b9612999b7bd2
humanhash: diet-enemy-india-dakota
File name:ccl
Download: download sample
File size:307 bytes
First seen:2026-05-08 18:29:49 UTC
Last seen:2026-05-09 06:59:37 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:h2UoLAWjGSMmWWaxAR9GRzLKochUOzNXsmIqwX5TCXD7m+bg6KNXYaF:vWAWMzWkARWnKochD1wX5GXDqiKiaF
TLSH T1C8E02B8A89D33CF3786A8C60DCBE1312AB11A4F76D2005243F03D1B19AE5A49B1B409D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
687
# of downloads :
8
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-06T16:52:00Z UTC
Last seen:
2026-05-10T12:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=4ff798fa-1a00-0000-1a61-e3934a080000 pid=2122 /usr/bin/sudo guuid=96f14cfc-1a00-0000-1a61-e3934e080000 pid=2126 /tmp/sample.bin guuid=4ff798fa-1a00-0000-1a61-e3934a080000 pid=2122->guuid=96f14cfc-1a00-0000-1a61-e3934e080000 pid=2126 execve guuid=1f1482fc-1a00-0000-1a61-e39350080000 pid=2128 /usr/bin/cp guuid=96f14cfc-1a00-0000-1a61-e3934e080000 pid=2126->guuid=1f1482fc-1a00-0000-1a61-e39350080000 pid=2128 execve guuid=a58d2afd-1a00-0000-1a61-e39352080000 pid=2130 /usr/bin/curl net guuid=96f14cfc-1a00-0000-1a61-e3934e080000 pid=2126->guuid=a58d2afd-1a00-0000-1a61-e39352080000 pid=2130 execve 7f9d5d61-c39d-58fe-965b-ede1f12734e8 85.239.151.41:80 guuid=a58d2afd-1a00-0000-1a61-e39352080000 pid=2130->7f9d5d61-c39d-58fe-965b-ede1f12734e8 con
Gathering data
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2026-05-06 19:57:52 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9e25f21a0eaff4358a3125a60b006b67369370bcaa62a96b033c2bfa445fef35

(this sample)

  
Delivery method
Distributed via web download

Comments