MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3acea557bea869639f7849419f3e4c7d1a58e09a13faee4adcddd954d692c32. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b3acea557bea869639f7849419f3e4c7d1a58e09a13faee4adcddd954d692c32
SHA3-384 hash: e6ff288fdb4aca3bbb071953ce958a90d281fbd47eeef92d1a17526d09bce2e3ced9382e6821b4dbd35a5ab5c29048dd
SHA1 hash: a3d763a522164e72e0ae4dc97d9191c6860cff69
MD5 hash: 0017987d6eece57935f48347350b4e88
humanhash: carolina-blossom-coffee-batman
File name:raw
Download: download sample
File size:4'807 bytes
First seen:2026-07-29 13:50:20 UTC
Last seen:2026-07-30 06:03:45 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:77VAQD0pDpVwEMjw5rub5NIZ5XQ5qsoAS99pI0Kn06wGG5EZfjiU:HOGjcubIzOoJ99ld6wGfYU
TLSH T15CA1ACF27808987161892E7478FB5C127667252FC212AE05B11776ED1C7BF99FF2C02A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
unix shell
First seen:
2026-07-20T06:05:00Z UTC
Last seen:
2026-07-20T06:14:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=791378c0-1c00-0000-ae12-4b82d80a0000 pid=2776 /usr/bin/sudo guuid=0438d0c2-1c00-0000-ae12-4b82df0a0000 pid=2783 /tmp/sample.bin guuid=791378c0-1c00-0000-ae12-4b82d80a0000 pid=2776->guuid=0438d0c2-1c00-0000-ae12-4b82df0a0000 pid=2783 execve guuid=0bba2dc3-1c00-0000-ae12-4b82e10a0000 pid=2785 /usr/bin/bash guuid=0438d0c2-1c00-0000-ae12-4b82df0a0000 pid=2783->guuid=0bba2dc3-1c00-0000-ae12-4b82e10a0000 pid=2785 clone guuid=aa9c3dc3-1c00-0000-ae12-4b82e20a0000 pid=2786 /usr/bin/cat guuid=0bba2dc3-1c00-0000-ae12-4b82e10a0000 pid=2785->guuid=aa9c3dc3-1c00-0000-ae12-4b82e20a0000 pid=2786 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-29 13:51:12 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b3acea557bea869639f7849419f3e4c7d1a58e09a13faee4adcddd954d692c32

(this sample)

  
Delivery method
Distributed via web download

Comments