MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a129de4fd4f1374a292bd8964df30c9e82c99bac680c4d36d6890fbf30ffac1c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a129de4fd4f1374a292bd8964df30c9e82c99bac680c4d36d6890fbf30ffac1c
SHA3-384 hash: 60962abaa0ce91e9dbc0f0a8a3148b22931f5bb5f3b1434ac89cb5507156018c8ab3841ff26ad736301196ca612ca3e4
SHA1 hash: 050962025dae3dcaef35135d3e60c4ad1f9a69ca
MD5 hash: 6222cb450999628bb61a4b3cbcd5f460
humanhash: failed-hydrogen-india-mockingbird
File name:malicious_post-checkout.sh
Download: download sample
File size:500 bytes
First seen:2026-07-15 22:51:47 UTC
Last seen:2026-07-15 22:53:00 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UmTR7aFTzXJcc/1Qz4CzXGnFFHEXe//FHEXeWFFTzXJccyn:UmUpzX6uQFzXmF1EX41EXHFpzX6V
TLSH T1E8F059B8C3789F3129CE0C2CCAE726B0818B335514E99DC4F7C6A8B1578A60DB314B01
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:ContagiousInterview DPRK githook Lazarus sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.172.103.226/301/301mn/an/aContagiousInterview DPRK InvisibleFerret Lazarus
http://144.172.103.226/301/301ln/an/aContagiousInterview DPRK InvisibleFerret Lazarus
http://144.172.103.226/301/301wn/an/aContagiousInterview DPRK InvisibleFerret Lazarus

Intelligence


File Origin
# of uploads :
2
# of downloads :
26
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-16T06:14:00Z UTC
Last seen:
2026-07-16T08:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=9e4bcd48-1900-0000-8a0d-d4f32e140000 pid=5166 /usr/bin/sudo guuid=0db0dd4a-1900-0000-8a0d-d4f32f140000 pid=5167 /tmp/sample.bin guuid=9e4bcd48-1900-0000-8a0d-d4f32e140000 pid=5166->guuid=0db0dd4a-1900-0000-8a0d-d4f32f140000 pid=5167 execve guuid=460d344b-1900-0000-8a0d-d4f330140000 pid=5168 /usr/bin/curl net send-data zombie guuid=0db0dd4a-1900-0000-8a0d-d4f32f140000 pid=5167->guuid=460d344b-1900-0000-8a0d-d4f330140000 pid=5168 execve guuid=ac24454b-1900-0000-8a0d-d4f331140000 pid=5169 /usr/bin/dash zombie guuid=0db0dd4a-1900-0000-8a0d-d4f32f140000 pid=5167->guuid=ac24454b-1900-0000-8a0d-d4f331140000 pid=5169 execve 4df10351-121e-5583-94fc-d602dcd1681f 144.172.103.226:80 guuid=460d344b-1900-0000-8a0d-d4f330140000 pid=5168->4df10351-121e-5583-94fc-d602dcd1681f send: 87B guuid=81c3a660-1900-0000-8a0d-d4f332140000 pid=5170 /usr/bin/mkdir guuid=ac24454b-1900-0000-8a0d-d4f331140000 pid=5169->guuid=81c3a660-1900-0000-8a0d-d4f332140000 pid=5170 execve guuid=9bffc461-1900-0000-8a0d-d4f333140000 pid=5171 /usr/bin/clear guuid=ac24454b-1900-0000-8a0d-d4f331140000 pid=5169->guuid=9bffc461-1900-0000-8a0d-d4f333140000 pid=5171 execve
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

sh a129de4fd4f1374a292bd8964df30c9e82c99bac680c4d36d6890fbf30ffac1c

(this sample)

Comments