MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aebd9ba42ede86bd173b5b645ed1877e5a9e92fa830eab213249faf8b09cfa42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: aebd9ba42ede86bd173b5b645ed1877e5a9e92fa830eab213249faf8b09cfa42
SHA3-384 hash: 24b4385e9f265b2e7a4caac4935ce6a5ec35a7dfc3fd09b1964c881093210601edeeda45265e4ec67fc3491852e38066
SHA1 hash: ddf60c04444828c7bae17ee6f84cf86db7291e9e
MD5 hash: 9dfbb8be172982fe03c7f8d33fc5ea37
humanhash: uniform-ink-papa-victor
File name:zed
Download: download sample
File size:27'994 bytes
First seen:2026-06-01 09:14:12 UTC
Last seen:Never
File type:
MIME type:text/x-perl
ssdeep 384:QssSHe4XDp2fv6Mf8JSN6WWabfd43+yZzB3l5:QssGe4XDp2fv5f8J7WWARy1B3D
TLSH T15EC2844919E34952A3B7F0761BDED4187A5BC1974B0DDE207DAC42DABF90039D2F8AC8
TrID 50.0% (.) Unix-like shebang (var.1) (gen) (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika perl
Reporter Blackdome
Tags:pl

Intelligence


File Origin
# of uploads :
1
# of downloads :
7
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-01T09:40:00Z UTC
Last seen:
2026-06-01T22:59:00Z UTC
Hits:
~10
Threat name:
Script-Perl.Backdoor.ShellBot
Status:
Malicious
First seen:
2026-06-01 10:53:12 UTC
File Type:
Text (Perl)
AV detection:
22 of 36 (61.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
linux
Behaviour
Changes its process name
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments