MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3d0ee25f77aaa1d74f6325ada58ba6beda3d0c760a2290451dedd36790942d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b3d0ee25f77aaa1d74f6325ada58ba6beda3d0c760a2290451dedd36790942d2
SHA3-384 hash: d940e6804a5d321beed25544220a9ef901bc0f8faffeec4c4fa1073d3f9adb77d1092c8aefd192663eb35e2a92c9633a
SHA1 hash: 35d2df0ec495d64ac33a2d6939309134422cd5a4
MD5 hash: 47e9e57d6fd86872a4efe2b87e0374f6
humanhash: montana-river-queen-mars
File name:b3d0ee25f77aaa1d74f6325ada58ba6beda3d0c760a2290451dedd36790942d2
Download: download sample
File size:814 bytes
First seen:2026-08-08 07:00:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:C0E2wFFaZX4JLVqrE7wgFFxQI9Aw6w7NNxtN6JXtUIx5lY4R:IaZX4JBqrPgxQI95X7NNxtN6JXtUIxT9
TLSH T1170185A278A74533F8BB443E6F2960A440EF01970E10ADD0B88E7D355F3AA20F007F02
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter EnthecSolutions
Tags:enthec sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Adware
File Type:
unix shell
First seen:
2026-08-06T01:43:00Z UTC
Last seen:
2026-08-09T21:16:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=9ad819e6-1600-0000-64f8-08c7640c0000 pid=3172 /usr/bin/sudo guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174 /tmp/sample.bin guuid=9ad819e6-1600-0000-64f8-08c7640c0000 pid=3172->guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174 execve guuid=853de4e7-1600-0000-64f8-08c7670c0000 pid=3175 /usr/bin/dash guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=853de4e7-1600-0000-64f8-08c7670c0000 pid=3175 clone guuid=c0840fe8-1600-0000-64f8-08c7680c0000 pid=3176 /usr/bin/uname guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=c0840fe8-1600-0000-64f8-08c7680c0000 pid=3176 execve guuid=98c178e8-1600-0000-64f8-08c76a0c0000 pid=3178 /usr/bin/curl net send-data write-file guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=98c178e8-1600-0000-64f8-08c76a0c0000 pid=3178 execve guuid=3aebebfa-1600-0000-64f8-08c78b0c0000 pid=3211 /usr/bin/chmod guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=3aebebfa-1600-0000-64f8-08c78b0c0000 pid=3211 execve guuid=f43941fb-1600-0000-64f8-08c78c0c0000 pid=3212 /tmp/.b write-file guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=f43941fb-1600-0000-64f8-08c78c0c0000 pid=3212 execve guuid=63d24ffb-1600-0000-64f8-08c78d0c0000 pid=3213 /usr/bin/sleep guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=63d24ffb-1600-0000-64f8-08c78d0c0000 pid=3213 execve guuid=dd9b5a73-1700-0000-64f8-08c7be0d0000 pid=3518 /usr/bin/rm delete-file guuid=9345a5e7-1600-0000-64f8-08c7660c0000 pid=3174->guuid=dd9b5a73-1700-0000-64f8-08c7be0d0000 pid=3518 execve 4aa37ddc-00af-5987-9deb-554203bf1e11 85.121.5.157:80 guuid=98c178e8-1600-0000-64f8-08c76a0c0000 pid=3178->4aa37ddc-00af-5987-9deb-554203bf1e11 send: 95B guuid=c50e48fc-1600-0000-64f8-08c78e0c0000 pid=3214 /tmp/.b zombie guuid=f43941fb-1600-0000-64f8-08c78c0c0000 pid=3212->guuid=c50e48fc-1600-0000-64f8-08c78e0c0000 pid=3214 clone guuid=be6850fc-1600-0000-64f8-08c78f0c0000 pid=3215 /tmp/.b delete-file net send-data zombie guuid=c50e48fc-1600-0000-64f8-08c78e0c0000 pid=3214->guuid=be6850fc-1600-0000-64f8-08c78f0c0000 pid=3215 clone d2202962-f5af-511b-9e06-f564bd5bf5f5 80.97.124.32:9000 guuid=be6850fc-1600-0000-64f8-08c78f0c0000 pid=3215->d2202962-f5af-511b-9e06-f564bd5bf5f5 send: 25B guuid=be6850fc-1600-0000-64f8-08c78f0c0000 pid=3216 /tmp/.b guuid=be6850fc-1600-0000-64f8-08c78f0c0000 pid=3215->guuid=be6850fc-1600-0000-64f8-08c78f0c0000 pid=3216 clone
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-08 10:06:15 UTC
AV detection:
4 of 38 (10.53%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads system network configuration
Checks hardware identifiers (DMI)
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments