MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b78899437b963811fcdb7807a1c8e4416fa13ec681023896df3b8d76fcb6dbcf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b78899437b963811fcdb7807a1c8e4416fa13ec681023896df3b8d76fcb6dbcf
SHA3-384 hash: 527ac234f56ebc205a5824a8051833093f29890ff0eb49e83e61d57f86426c1bc60152232b5beffc8a9e07497c90f2ac
SHA1 hash: 1f4ee83ebd9065629d4dddb721dc08eceddafbd6
MD5 hash: b88602a0db0f6700a3a4d62e1c7f964c
humanhash: carolina-mountain-bulldog-failed
File name:all.sh
Download: download sample
File size:736 bytes
First seen:2026-01-21 22:31:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:YkF1kcClZF70TGAf/HFKf/HFTf/HFWjLlRBFSrL8+FM5gFiLEjLlRBFSVL8+FMD1:ZDkH/FlK/HFs/HFL/HFWj5F6hFM5gFiK
TLSH T1C301B194313461B075BEDCE64E72AC1831C990D63DC67FB97C67B0DAA5A5D00B8A20B9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.79.9/huhu/titanjr.n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-21T13:17:00Z UTC
Last seen:
2026-01-21T17:05:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=6a45f583-1a00-0000-02ae-c2c44c080000 pid=2124 /usr/bin/sudo guuid=d85b9186-1a00-0000-02ae-c2c452080000 pid=2130 /tmp/sample.bin guuid=6a45f583-1a00-0000-02ae-c2c44c080000 pid=2124->guuid=d85b9186-1a00-0000-02ae-c2c452080000 pid=2130 execve guuid=f62b1487-1a00-0000-02ae-c2c454080000 pid=2132 /usr/bin/wget guuid=d85b9186-1a00-0000-02ae-c2c452080000 pid=2130->guuid=f62b1487-1a00-0000-02ae-c2c454080000 pid=2132 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b78899437b963811fcdb7807a1c8e4416fa13ec681023896df3b8d76fcb6dbcf

(this sample)

  
Delivery method
Distributed via web download

Comments