🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7bce3a6c5cf2d70d11c0c8e1cfebb4a6ffd7ce7bda7f3889ec6d391e9c4abcc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a7bce3a6c5cf2d70d11c0c8e1cfebb4a6ffd7ce7bda7f3889ec6d391e9c4abcc
SHA3-384 hash: ce09b8ce416bc45ae9c4098d1bb8853ad2fe109e4b202645750070a552184c4a2d20862e893ba5bf99e473844113da84
SHA1 hash: 3a05d487c9beea95a7b154bc33f04a25a2a0ebf0
MD5 hash: f6b0bd31c7e13ed546dc5eb359192591
humanhash: arkansas-helium-item-friend
File name:q.sh
Download: download sample
File size:2'363 bytes
First seen:2026-09-29 14:48:00 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:v9NYw0srRv69nRFlNvnRGmOajTPFnkPL/2RJR2OaRcmxPLRFn4lH7ZMZaqs:vLYz/RlF2z/2RDMcoPlGlx
TLSH T155412EEDFA70CD707E088538F6ED616454470E3F48763856F42F85680A5C028B37E762
Magika shell
Reporter smica83
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://131.123.43.239/upn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash lolbin opendir
Verdict:
Unknown
File Type:
ps1
First seen:
2026-09-30T03:32:00Z UTC
Last seen:
2026-09-30T03:35:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=489a8817-1c00-0000-10a8-5ee8880b0000 pid=2952 /usr/bin/sudo guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961 /tmp/sample.bin guuid=489a8817-1c00-0000-10a8-5ee8880b0000 pid=2952->guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961 execve guuid=a05da81a-1c00-0000-10a8-5ee8920b0000 pid=2962 /usr/bin/dash zombie guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961->guuid=a05da81a-1c00-0000-10a8-5ee8920b0000 pid=2962 clone guuid=3918b11a-1c00-0000-10a8-5ee8930b0000 pid=2963 /usr/bin/flock guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961->guuid=3918b11a-1c00-0000-10a8-5ee8930b0000 pid=2963 execve guuid=7192361b-1c00-0000-10a8-5ee8990b0000 pid=2969 /usr/bin/dash guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961->guuid=7192361b-1c00-0000-10a8-5ee8990b0000 pid=2969 clone guuid=ee0a411b-1c00-0000-10a8-5ee89a0b0000 pid=2970 /usr/bin/dash guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961->guuid=ee0a411b-1c00-0000-10a8-5ee89a0b0000 pid=2970 clone guuid=f118d61b-1c00-0000-10a8-5ee8a00b0000 pid=2976 /usr/bin/touch guuid=e276661a-1c00-0000-10a8-5ee8910b0000 pid=2961->guuid=f118d61b-1c00-0000-10a8-5ee8a00b0000 pid=2976 execve guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964 /usr/bin/dash guuid=a05da81a-1c00-0000-10a8-5ee8920b0000 pid=2962->guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964 clone guuid=7d90ba1a-1c00-0000-10a8-5ee8950b0000 pid=2965 /usr/bin/base64 guuid=a05da81a-1c00-0000-10a8-5ee8920b0000 pid=2962->guuid=7d90ba1a-1c00-0000-10a8-5ee8950b0000 pid=2965 execve guuid=8acec51a-1c00-0000-10a8-5ee8970b0000 pid=2967 /usr/bin/xargs guuid=a05da81a-1c00-0000-10a8-5ee8920b0000 pid=2962->guuid=8acec51a-1c00-0000-10a8-5ee8970b0000 pid=2967 execve guuid=1f00bc1a-1c00-0000-10a8-5ee8960b0000 pid=2966 /usr/bin/ip guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=1f00bc1a-1c00-0000-10a8-5ee8960b0000 pid=2966 execve guuid=fe3fca1b-1c00-0000-10a8-5ee89e0b0000 pid=2974 /usr/bin/id guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=fe3fca1b-1c00-0000-10a8-5ee89e0b0000 pid=2974 execve guuid=d4da631c-1c00-0000-10a8-5ee8a30b0000 pid=2979 /usr/bin/w guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=d4da631c-1c00-0000-10a8-5ee8a30b0000 pid=2979 execve guuid=5aa7da1d-1c00-0000-10a8-5ee8a60b0000 pid=2982 /usr/bin/ps guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=5aa7da1d-1c00-0000-10a8-5ee8a60b0000 pid=2982 execve guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2991 /usr/bin/curl net send-data guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2991 execve guuid=f59a082e-1c00-0000-10a8-5ee8c70b0000 pid=3015 /usr/bin/cat guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=f59a082e-1c00-0000-10a8-5ee8c70b0000 pid=3015 execve guuid=a87c112e-1c00-0000-10a8-5ee8c80b0000 pid=3016 /usr/bin/head guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=a87c112e-1c00-0000-10a8-5ee8c80b0000 pid=3016 execve guuid=14d6362f-1c00-0000-10a8-5ee8cb0b0000 pid=3019 /usr/bin/ls guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=14d6362f-1c00-0000-10a8-5ee8cb0b0000 pid=3019 execve guuid=21df412f-1c00-0000-10a8-5ee8cc0b0000 pid=3020 /usr/bin/head guuid=4145b31a-1c00-0000-10a8-5ee8940b0000 pid=2964->guuid=21df412f-1c00-0000-10a8-5ee8cc0b0000 pid=3020 execve guuid=c16a6330-1c00-0000-10a8-5ee8ce0b0000 pid=3022 /usr/bin/curl net send-data guuid=8acec51a-1c00-0000-10a8-5ee8970b0000 pid=2967->guuid=c16a6330-1c00-0000-10a8-5ee8ce0b0000 pid=3022 execve guuid=3200531b-1c00-0000-10a8-5ee89c0b0000 pid=2972 /usr/bin/dash guuid=7192361b-1c00-0000-10a8-5ee8990b0000 pid=2969->guuid=3200531b-1c00-0000-10a8-5ee89c0b0000 pid=2972 clone guuid=e363571b-1c00-0000-10a8-5ee89d0b0000 pid=2973 /usr/bin/grep guuid=7192361b-1c00-0000-10a8-5ee8990b0000 pid=2969->guuid=e363571b-1c00-0000-10a8-5ee89d0b0000 pid=2973 execve e1f9bcbd-fc59-5429-9359-3d4eca276af4 ifconfig.me:80 guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2991->e1f9bcbd-fc59-5429-9359-3d4eca276af4 send: 75B guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2999 /usr/bin/curl dns net send-data guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2991->guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2999 clone guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2999->e1f9bcbd-fc59-5429-9359-3d4eca276af4 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=6c4b1722-1c00-0000-10a8-5ee8af0b0000 pid=2999->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 58B d7b95afe-aef2-53b3-baca-4e8618f4bd8e 131.123.43.239:80 guuid=c16a6330-1c00-0000-10a8-5ee8ce0b0000 pid=3022->d7b95afe-aef2-53b3-baca-4e8618f4bd8e send: 18667B
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments