MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a927d846000150182ceb79dc90494dff0d36acffd5aa78f793c110eae5694c2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a927d846000150182ceb79dc90494dff0d36acffd5aa78f793c110eae5694c2f
SHA3-384 hash: 6727fd379b6b80218e0858749c9be0bde3aaac64917fd3bbee2b6318da52b880fead9d115fce38a0de2428c35e761265
SHA1 hash: 9894c275621f94ecb023f90275e1da7e6c719618
MD5 hash: dd4badb66fc97b03d4fd9cbb7563a937
humanhash: happy-arkansas-neptune-five
File name:bbc
Download: download sample
File size:499 bytes
First seen:2026-08-13 02:26:01 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:lSjhh1OL9ephRjk4Y4bou7Co1VOq2xddNizdI/HXu81lmXx:lk1gYpTr8i3fOq2bf8IGMAh
TLSH T10DF08C03A48BF036808439A8EB76F75AFC24BC476262CE4CB840BA50EED74247861240
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://109.248.160.75/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=aaad43c5-1700-0000-1b57-766af10a0000 pid=2801 /usr/bin/sudo guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807 /tmp/sample.bin guuid=aaad43c5-1700-0000-1b57-766af10a0000 pid=2801->guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807 execve guuid=7fa144c7-1700-0000-1b57-766af80a0000 pid=2808 /usr/bin/uname guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=7fa144c7-1700-0000-1b57-766af80a0000 pid=2808 execve guuid=97e43cc8-1700-0000-1b57-766af90a0000 pid=2809 /usr/bin/rm guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=97e43cc8-1700-0000-1b57-766af90a0000 pid=2809 execve guuid=f20cf2c8-1700-0000-1b57-766afa0a0000 pid=2810 /usr/bin/busybox net send-data write-file guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=f20cf2c8-1700-0000-1b57-766afa0a0000 pid=2810 execve guuid=f7d8141e-1800-0000-1b57-766ac70b0000 pid=3015 /usr/bin/chmod guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=f7d8141e-1800-0000-1b57-766ac70b0000 pid=3015 execve guuid=97a04e1e-1800-0000-1b57-766ac90b0000 pid=3017 /tmp/data_x86_64 net guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=97a04e1e-1800-0000-1b57-766ac90b0000 pid=3017 execve guuid=e6a4851e-1800-0000-1b57-766acc0b0000 pid=3020 /usr/bin/rm delete-file guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=e6a4851e-1800-0000-1b57-766acc0b0000 pid=3020 execve guuid=f394bd1e-1800-0000-1b57-766ad20b0000 pid=3026 /usr/bin/rm delete-file guuid=a801fbc6-1700-0000-1b57-766af70a0000 pid=2807->guuid=f394bd1e-1800-0000-1b57-766ad20b0000 pid=3026 execve 4295823a-efd9-505a-a6de-bbca4b3427eb 109.248.160.75:80 guuid=f20cf2c8-1700-0000-1b57-766afa0a0000 pid=2810->4295823a-efd9-505a-a6de-bbca4b3427eb send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=97a04e1e-1800-0000-1b57-766ac90b0000 pid=3017->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7eb57b1e-1800-0000-1b57-766aca0b0000 pid=3018 /tmp/data_x86_64 zombie guuid=97a04e1e-1800-0000-1b57-766ac90b0000 pid=3017->guuid=7eb57b1e-1800-0000-1b57-766aca0b0000 pid=3018 clone guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021 /tmp/data_x86_64 net send-data write-file zombie guuid=7eb57b1e-1800-0000-1b57-766aca0b0000 pid=3018->guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021 clone guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 120B 078eade7-3095-5267-a77b-87ee2e5068f0 169.58.168.81:8082 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->078eade7-3095-5267-a77b-87ee2e5068f0 con b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 120B 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->54d92a3b-1447-55af-b534-047898c60c8d send: 120B guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3022 /tmp/data_x86_64 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3022 clone guuid=f337ae1e-1800-0000-1b57-766acf0b0000 pid=3023 /tmp/data_x86_64 net write-file guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=f337ae1e-1800-0000-1b57-766acf0b0000 pid=3023 clone guuid=2373b31e-1800-0000-1b57-766ad00b0000 pid=3024 /tmp/data_x86_64 delete-file net send-data guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=2373b31e-1800-0000-1b57-766ad00b0000 pid=3024 clone guuid=eafefe1e-1800-0000-1b57-766ad40b0000 pid=3028 /tmp/data_x86_64 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=eafefe1e-1800-0000-1b57-766ad40b0000 pid=3028 clone guuid=927a9b24-1800-0000-1b57-766ae20b0000 pid=3042 /tmp/data_x86_64 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=927a9b24-1800-0000-1b57-766ae20b0000 pid=3042 clone guuid=5280ae24-1800-0000-1b57-766ae30b0000 pid=3043 /tmp/data_x86_64 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=5280ae24-1800-0000-1b57-766ae30b0000 pid=3043 clone guuid=5e95a4ab-2100-0000-1b57-766a6d150000 pid=5485 /tmp/data_x86_64 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=5e95a4ab-2100-0000-1b57-766a6d150000 pid=5485 clone guuid=df46e1ab-2100-0000-1b57-766a6e150000 pid=5486 /tmp/data_x86_64 guuid=a014871e-1800-0000-1b57-766acd0b0000 pid=3021->guuid=df46e1ab-2100-0000-1b57-766a6e150000 pid=5486 clone a15c7036-706e-5ee9-888f-734cbb9e72e7 127.0.0.1:30565 guuid=f337ae1e-1800-0000-1b57-766acf0b0000 pid=3023->a15c7036-706e-5ee9-888f-734cbb9e72e7 con guuid=2373b31e-1800-0000-1b57-766ad00b0000 pid=3024->a15c7036-706e-5ee9-888f-734cbb9e72e7 send: 18960B
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a927d846000150182ceb79dc90494dff0d36acffd5aa78f793c110eae5694c2f

(this sample)

  
Delivery method
Distributed via web download

Comments