MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a4edaaf6c5334e2aeb012373417074434d77cc1a72a9840eb6ae0d95ee1f08d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a4edaaf6c5334e2aeb012373417074434d77cc1a72a9840eb6ae0d95ee1f08d6
SHA3-384 hash: 1529b115b5b645165cd091fa2db4782c4bb88a44f74fec7f5d26b46244a7a2104561ba19eb3e63218d33469553ea78d7
SHA1 hash: c3beb1258ef27292fe4d7e86ecffcd6bef15050e
MD5 hash: d383fb1eeca1fa3a4d3463fd70f764dd
humanhash: may-romeo-rugby-pip
File name:w2.sh
Download: download sample
File size:345 bytes
First seen:2026-07-09 04:48:36 UTC
Last seen:2026-07-09 13:38:47 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:+Ycy+JF+OuyzvCCpFpoavx69R0wu+4k/GCafRR0/0su6MMJN:+Cm+OuyLCEUavx6v0/+4k/uJR0NJ
TLSH T10CE02660FB5052B833E083B55A4AF1453A161FF20B442979F48A259530A084E78368FA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
3
# of downloads :
68
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
unix shell
First seen:
2026-07-09T02:07:00Z UTC
Last seen:
2026-07-09T18:05:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=736cfdf8-1800-0000-a4af-a5ae24140000 pid=5156 /usr/bin/sudo guuid=770314fb-1800-0000-a4af-a5ae25140000 pid=5157 /tmp/sample.bin guuid=736cfdf8-1800-0000-a4af-a5ae24140000 pid=5156->guuid=770314fb-1800-0000-a4af-a5ae25140000 pid=5157 execve guuid=b0f910fc-1800-0000-a4af-a5ae26140000 pid=5158 /usr/bin/ps guuid=770314fb-1800-0000-a4af-a5ae25140000 pid=5157->guuid=b0f910fc-1800-0000-a4af-a5ae26140000 pid=5158 execve guuid=df9ce802-1900-0000-a4af-a5ae27140000 pid=5159 /usr/bin/bash guuid=770314fb-1800-0000-a4af-a5ae25140000 pid=5157->guuid=df9ce802-1900-0000-a4af-a5ae27140000 pid=5159 clone guuid=23b86403-1900-0000-a4af-a5ae2a140000 pid=5162 /usr/bin/bash guuid=770314fb-1800-0000-a4af-a5ae25140000 pid=5157->guuid=23b86403-1900-0000-a4af-a5ae2a140000 pid=5162 clone guuid=0ccbfa02-1900-0000-a4af-a5ae28140000 pid=5160 /usr/bin/bash guuid=df9ce802-1900-0000-a4af-a5ae27140000 pid=5159->guuid=0ccbfa02-1900-0000-a4af-a5ae28140000 pid=5160 clone guuid=49170303-1900-0000-a4af-a5ae29140000 pid=5161 /usr/bin/mawk guuid=df9ce802-1900-0000-a4af-a5ae27140000 pid=5159->guuid=49170303-1900-0000-a4af-a5ae29140000 pid=5161 execve
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Reads CPU attributes
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a4edaaf6c5334e2aeb012373417074434d77cc1a72a9840eb6ae0d95ee1f08d6

(this sample)

  
Delivery method
Distributed via web download

Comments