MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa3803a34237fabfd445dd8a7ed0853168f2bdce7289e38b0fc3f1260d2e3cf4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: aa3803a34237fabfd445dd8a7ed0853168f2bdce7289e38b0fc3f1260d2e3cf4
SHA3-384 hash: d1641126d403e1c7d1507b8253489930bfa8755678e175a0f795918c85fe1b53da12c5113d5ae26c74ecac988945054c
SHA1 hash: 0e8750cb794920fb4a3b37dd8dd2de171ec293b1
MD5 hash: 6c8e6c9fa700c8000a26137fa5ea6502
humanhash: alanine-tennis-lion-virginia
File name:tftp.sh
Download: download sample
File size:945 bytes
First seen:2025-12-25 19:18:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:ovzs6gzVbkObG+Nn/5Zxn7LKQzOOjbin+VVnmSv3Dt2OzlByPcHv:5lG0PPKQy6i+LmATtZgPw
TLSH T1181151BF28111E7B8D0A8D9DD52784B064D399C07E031D516B1768B8CCEF228BB659E9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
unix shell
First seen:
2025-12-25T16:37:00Z UTC
Last seen:
2025-12-26T17:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=68c85c2b-1a00-0000-5b89-556865090000 pid=2405 /usr/bin/sudo guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413 /tmp/sample.bin guuid=68c85c2b-1a00-0000-5b89-556865090000 pid=2405->guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413 execve guuid=ff06d02e-1a00-0000-5b89-55686f090000 pid=2415 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=ff06d02e-1a00-0000-5b89-55686f090000 pid=2415 clone guuid=a920f72e-1a00-0000-5b89-556870090000 pid=2416 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=a920f72e-1a00-0000-5b89-556870090000 pid=2416 execve guuid=a0814e2f-1a00-0000-5b89-556872090000 pid=2418 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=a0814e2f-1a00-0000-5b89-556872090000 pid=2418 clone guuid=008f952f-1a00-0000-5b89-556873090000 pid=2419 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=008f952f-1a00-0000-5b89-556873090000 pid=2419 clone guuid=27d4b42f-1a00-0000-5b89-556874090000 pid=2420 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=27d4b42f-1a00-0000-5b89-556874090000 pid=2420 execve guuid=13a1ff2f-1a00-0000-5b89-556876090000 pid=2422 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=13a1ff2f-1a00-0000-5b89-556876090000 pid=2422 clone guuid=14f42030-1a00-0000-5b89-556877090000 pid=2423 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=14f42030-1a00-0000-5b89-556877090000 pid=2423 clone guuid=16303830-1a00-0000-5b89-556878090000 pid=2424 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=16303830-1a00-0000-5b89-556878090000 pid=2424 execve guuid=28747f30-1a00-0000-5b89-55687a090000 pid=2426 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=28747f30-1a00-0000-5b89-55687a090000 pid=2426 clone guuid=9c259c30-1a00-0000-5b89-55687c090000 pid=2428 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=9c259c30-1a00-0000-5b89-55687c090000 pid=2428 clone guuid=c3c2ab30-1a00-0000-5b89-55687d090000 pid=2429 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=c3c2ab30-1a00-0000-5b89-55687d090000 pid=2429 execve guuid=5fc7fc30-1a00-0000-5b89-55687f090000 pid=2431 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=5fc7fc30-1a00-0000-5b89-55687f090000 pid=2431 clone guuid=a0081231-1a00-0000-5b89-556880090000 pid=2432 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=a0081231-1a00-0000-5b89-556880090000 pid=2432 clone guuid=86d72e31-1a00-0000-5b89-556881090000 pid=2433 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=86d72e31-1a00-0000-5b89-556881090000 pid=2433 execve guuid=a6237031-1a00-0000-5b89-556883090000 pid=2435 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=a6237031-1a00-0000-5b89-556883090000 pid=2435 clone guuid=5db68c31-1a00-0000-5b89-556884090000 pid=2436 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=5db68c31-1a00-0000-5b89-556884090000 pid=2436 clone guuid=6404a031-1a00-0000-5b89-556885090000 pid=2437 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=6404a031-1a00-0000-5b89-556885090000 pid=2437 execve guuid=b317dd31-1a00-0000-5b89-556887090000 pid=2439 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=b317dd31-1a00-0000-5b89-556887090000 pid=2439 clone guuid=5733f831-1a00-0000-5b89-556889090000 pid=2441 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=5733f831-1a00-0000-5b89-556889090000 pid=2441 clone guuid=8a8f2832-1a00-0000-5b89-55688a090000 pid=2442 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=8a8f2832-1a00-0000-5b89-55688a090000 pid=2442 execve guuid=802bd632-1a00-0000-5b89-55688d090000 pid=2445 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=802bd632-1a00-0000-5b89-55688d090000 pid=2445 clone guuid=1be70633-1a00-0000-5b89-55688f090000 pid=2447 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=1be70633-1a00-0000-5b89-55688f090000 pid=2447 clone guuid=0bea2a33-1a00-0000-5b89-556890090000 pid=2448 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=0bea2a33-1a00-0000-5b89-556890090000 pid=2448 execve guuid=ce22c633-1a00-0000-5b89-556893090000 pid=2451 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=ce22c633-1a00-0000-5b89-556893090000 pid=2451 clone guuid=3029df33-1a00-0000-5b89-556894090000 pid=2452 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=3029df33-1a00-0000-5b89-556894090000 pid=2452 clone guuid=af8e1734-1a00-0000-5b89-556895090000 pid=2453 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=af8e1734-1a00-0000-5b89-556895090000 pid=2453 execve guuid=841d7534-1a00-0000-5b89-556897090000 pid=2455 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=841d7534-1a00-0000-5b89-556897090000 pid=2455 clone guuid=f16a8a34-1a00-0000-5b89-556898090000 pid=2456 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=f16a8a34-1a00-0000-5b89-556898090000 pid=2456 clone guuid=ebf6a234-1a00-0000-5b89-55689a090000 pid=2458 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=ebf6a234-1a00-0000-5b89-55689a090000 pid=2458 execve guuid=da56fe34-1a00-0000-5b89-55689c090000 pid=2460 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=da56fe34-1a00-0000-5b89-55689c090000 pid=2460 clone guuid=fe911535-1a00-0000-5b89-55689d090000 pid=2461 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=fe911535-1a00-0000-5b89-55689d090000 pid=2461 clone guuid=70793035-1a00-0000-5b89-55689f090000 pid=2463 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=70793035-1a00-0000-5b89-55689f090000 pid=2463 execve guuid=a9b47635-1a00-0000-5b89-5568a0090000 pid=2464 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=a9b47635-1a00-0000-5b89-5568a0090000 pid=2464 clone guuid=68fa9235-1a00-0000-5b89-5568a2090000 pid=2466 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=68fa9235-1a00-0000-5b89-5568a2090000 pid=2466 clone guuid=c960d035-1a00-0000-5b89-5568a3090000 pid=2467 /usr/bin/chmod guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=c960d035-1a00-0000-5b89-5568a3090000 pid=2467 execve guuid=ed323736-1a00-0000-5b89-5568a6090000 pid=2470 /usr/bin/bash guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=ed323736-1a00-0000-5b89-5568a6090000 pid=2470 clone guuid=bc885036-1a00-0000-5b89-5568a7090000 pid=2471 /usr/bin/rm delete-file guuid=c088492e-1a00-0000-5b89-55686d090000 pid=2413->guuid=bc885036-1a00-0000-5b89-5568a7090000 pid=2471 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-25 19:19:40 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh aa3803a34237fabfd445dd8a7ed0853168f2bdce7289e38b0fc3f1260d2e3cf4

(this sample)

  
Delivery method
Distributed via web download

Comments