MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac48d17645e060f4ce0b9e22c43e7175ecc0c304fb2a4a3cc8a377a0548f2fed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ac48d17645e060f4ce0b9e22c43e7175ecc0c304fb2a4a3cc8a377a0548f2fed
SHA3-384 hash: 1776ff8b044a35ceb3f997c4c4bd11c669b9d8c42aa55ec0d626e313ca578a729cade4478e1847ef0e7a3da43fa00520
SHA1 hash: a9e054e0ba6c6ed134d69c144714cb6f6ab448e3
MD5 hash: cbfd16a655e1fb1ab26d45137339f09b
humanhash: king-may-four-orange
File name:loader.sh
Download: download sample
File size:1'470 bytes
First seen:2026-08-03 02:02:11 UTC
Last seen:2026-08-03 07:44:11 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:rjLhUWKqJMaXMMdSRmBLrZsCD6yqJpYX8vpvpIrlgPocoLH:rPfKqJMANdSRmBLNsCuyqJSXAVH4H
TLSH T1BD31BCD9B090B132B489E7FCEF1EAF5875033AAD75648E0894F17C64E66D8047C8A5E0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://95.164.53.73/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-25T23:02:00Z UTC
Last seen:
2026-08-01T21:35:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cb2e19cc-1700-0000-40dc-7611c9090000 pid=2505 /usr/bin/sudo guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510 /tmp/sample.bin guuid=cb2e19cc-1700-0000-40dc-7611c9090000 pid=2505->guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510 execve guuid=5cfef3cd-1700-0000-40dc-7611d0090000 pid=2512 /usr/bin/uname guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=5cfef3cd-1700-0000-40dc-7611d0090000 pid=2512 execve guuid=be8432ce-1700-0000-40dc-7611d2090000 pid=2514 /usr/bin/dash guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=be8432ce-1700-0000-40dc-7611d2090000 pid=2514 clone guuid=2dfb7ece-1700-0000-40dc-7611d4090000 pid=2516 /usr/bin/basename guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=2dfb7ece-1700-0000-40dc-7611d4090000 pid=2516 execve guuid=c0bbb9ce-1700-0000-40dc-7611d6090000 pid=2518 /usr/bin/wget net send-data write-file guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=c0bbb9ce-1700-0000-40dc-7611d6090000 pid=2518 execve guuid=bd9977d5-1700-0000-40dc-7611e8090000 pid=2536 /usr/bin/chmod guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=bd9977d5-1700-0000-40dc-7611e8090000 pid=2536 execve guuid=addbb1d5-1700-0000-40dc-7611ea090000 pid=2538 /usr/bin/dash guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=addbb1d5-1700-0000-40dc-7611ea090000 pid=2538 clone guuid=2d16b5d5-1700-0000-40dc-7611eb090000 pid=2539 /usr/bin/rm delete-file guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=2d16b5d5-1700-0000-40dc-7611eb090000 pid=2539 execve guuid=3453fed5-1700-0000-40dc-7611ed090000 pid=2541 /usr/bin/rm delete-file guuid=980bc5cd-1700-0000-40dc-7611ce090000 pid=2510->guuid=3453fed5-1700-0000-40dc-7611ed090000 pid=2541 execve guuid=73dd3ace-1700-0000-40dc-7611d3090000 pid=2515 /usr/bin/dirname guuid=be8432ce-1700-0000-40dc-7611d2090000 pid=2514->guuid=73dd3ace-1700-0000-40dc-7611d3090000 pid=2515 execve b94f35a3-b372-5bab-abff-74c341421c5c 95.164.53.73:80 guuid=c0bbb9ce-1700-0000-40dc-7611d6090000 pid=2518->b94f35a3-b372-5bab-abff-74c341421c5c send: 137B
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads process memory
UPX packed file
Creates/modifies Cron job
Enumerates running processes
Modifies init.d
Reads MAC address of network interface
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Runs EXE from memory
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ac48d17645e060f4ce0b9e22c43e7175ecc0c304fb2a4a3cc8a377a0548f2fed

(this sample)

  
Delivery method
Distributed via web download

Comments