MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7d8c602e19344b7ed2cb6c13e3d4a8a2c3ec4d2106227e73cbe8916a3201f29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: b7d8c602e19344b7ed2cb6c13e3d4a8a2c3ec4d2106227e73cbe8916a3201f29
SHA3-384 hash: d1b375f48d3ff83285f4347618a87ffb65499c4ac07a49d3c49d4fb44322a052bf48fc6f2e5b9427a7f5c0d576428919
SHA1 hash: 53bc31c9f4781699e5ad84f76a7ddf066f206d77
MD5 hash: a109135159b83fadd59c26637d39118a
humanhash: colorado-lake-queen-oscar
File name:kamru.sh
Download: download sample
File size:642 bytes
First seen:2026-05-01 18:32:07 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:j+AjNMZeT2qF2k4KYjKyI4FKydWs+X3s7DesCn/tiO4K84y3d7P:j+AGZcAKY+yIFydWs+X3sWTDy31
TLSH T14FF0ACC2211005B03A684F0BD0C77284D16E2D139AC7BE3039CE7A508BAECAEF284674
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=fc76cead-1800-0000-8fa6-7554c40b0000 pid=3012 /usr/bin/sudo guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019 /tmp/sample.bin guuid=fc76cead-1800-0000-8fa6-7554c40b0000 pid=3012->guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019 execve guuid=e5ca4ab0-1800-0000-8fa6-7554cc0b0000 pid=3020 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=e5ca4ab0-1800-0000-8fa6-7554cc0b0000 pid=3020 execve guuid=bf09d7ba-1800-0000-8fa6-7554e50b0000 pid=3045 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=bf09d7ba-1800-0000-8fa6-7554e50b0000 pid=3045 execve guuid=565c52bb-1800-0000-8fa6-7554e70b0000 pid=3047 /tmp/k.x86 guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=565c52bb-1800-0000-8fa6-7554e70b0000 pid=3047 execve guuid=d12656bb-1800-0000-8fa6-7554e80b0000 pid=3048 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=d12656bb-1800-0000-8fa6-7554e80b0000 pid=3048 execve guuid=abba8ef7-1800-0000-8fa6-75546b0c0000 pid=3179 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=abba8ef7-1800-0000-8fa6-75546b0c0000 pid=3179 execve guuid=70be35fd-1800-0000-8fa6-75546c0c0000 pid=3180 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=70be35fd-1800-0000-8fa6-75546c0c0000 pid=3180 execve guuid=eb43a4fd-1800-0000-8fa6-75546d0c0000 pid=3181 /tmp/k.mips guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=eb43a4fd-1800-0000-8fa6-75546d0c0000 pid=3181 execve guuid=f583b4fd-1800-0000-8fa6-75546e0c0000 pid=3182 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=f583b4fd-1800-0000-8fa6-75546e0c0000 pid=3182 execve guuid=6896683a-1900-0000-8fa6-7554b10c0000 pid=3249 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=6896683a-1900-0000-8fa6-7554b10c0000 pid=3249 execve guuid=e1b21441-1900-0000-8fa6-7554bb0c0000 pid=3259 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=e1b21441-1900-0000-8fa6-7554bb0c0000 pid=3259 execve guuid=1a5c5841-1900-0000-8fa6-7554bd0c0000 pid=3261 /tmp/k.mipsel guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=1a5c5841-1900-0000-8fa6-7554bd0c0000 pid=3261 execve guuid=51b46141-1900-0000-8fa6-7554be0c0000 pid=3262 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=51b46141-1900-0000-8fa6-7554be0c0000 pid=3262 execve guuid=27a2ab7d-1900-0000-8fa6-75541c0d0000 pid=3356 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=27a2ab7d-1900-0000-8fa6-75541c0d0000 pid=3356 execve guuid=9c048182-1900-0000-8fa6-7554240d0000 pid=3364 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=9c048182-1900-0000-8fa6-7554240d0000 pid=3364 execve guuid=6ab40483-1900-0000-8fa6-7554250d0000 pid=3365 /tmp/k.arm guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=6ab40483-1900-0000-8fa6-7554250d0000 pid=3365 execve guuid=88ab0d83-1900-0000-8fa6-7554260d0000 pid=3366 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=88ab0d83-1900-0000-8fa6-7554260d0000 pid=3366 execve guuid=9b1a7bbf-1900-0000-8fa6-7554b20d0000 pid=3506 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=9b1a7bbf-1900-0000-8fa6-7554b20d0000 pid=3506 execve guuid=5186e2c5-1900-0000-8fa6-7554b80d0000 pid=3512 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=5186e2c5-1900-0000-8fa6-7554b80d0000 pid=3512 execve guuid=51be24c6-1900-0000-8fa6-7554ba0d0000 pid=3514 /tmp/k.arm7 mprotect-exec guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=51be24c6-1900-0000-8fa6-7554ba0d0000 pid=3514 execve guuid=e8ad27c6-1900-0000-8fa6-7554bb0d0000 pid=3515 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=e8ad27c6-1900-0000-8fa6-7554bb0d0000 pid=3515 execve guuid=b16c0b02-1a00-0000-8fa6-7554dc0d0000 pid=3548 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=b16c0b02-1a00-0000-8fa6-7554dc0d0000 pid=3548 execve guuid=f0e0a808-1a00-0000-8fa6-7554e50d0000 pid=3557 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=f0e0a808-1a00-0000-8fa6-7554e50d0000 pid=3557 execve guuid=75151d09-1a00-0000-8fa6-7554e70d0000 pid=3559 /tmp/k.ppc guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=75151d09-1a00-0000-8fa6-7554e70d0000 pid=3559 execve guuid=c8e82309-1a00-0000-8fa6-7554e80d0000 pid=3560 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=c8e82309-1a00-0000-8fa6-7554e80d0000 pid=3560 execve guuid=74f15845-1a00-0000-8fa6-7554670e0000 pid=3687 /usr/bin/wget net send-data write-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=74f15845-1a00-0000-8fa6-7554670e0000 pid=3687 execve guuid=ebb13251-1a00-0000-8fa6-7554740e0000 pid=3700 /usr/bin/chmod guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=ebb13251-1a00-0000-8fa6-7554740e0000 pid=3700 execve guuid=d9099051-1a00-0000-8fa6-7554750e0000 pid=3701 /tmp/k.x86_64 guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=d9099051-1a00-0000-8fa6-7554750e0000 pid=3701 execve guuid=fb009651-1a00-0000-8fa6-7554760e0000 pid=3702 /usr/bin/sleep guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=fb009651-1a00-0000-8fa6-7554760e0000 pid=3702 execve guuid=a63b8d8d-1a00-0000-8fa6-7554280f0000 pid=3880 /usr/bin/rm delete-file guuid=d6d10db0-1800-0000-8fa6-7554cb0b0000 pid=3019->guuid=a63b8d8d-1a00-0000-8fa6-7554280f0000 pid=3880 execve 72a78419-8065-5ec7-93ba-cdb426fb221b 176.65.139.161:80 guuid=e5ca4ab0-1800-0000-8fa6-7554cc0b0000 pid=3020->72a78419-8065-5ec7-93ba-cdb426fb221b send: 143B guuid=d481e5bb-1800-0000-8fa6-7554eb0b0000 pid=3051 /tmp/k.x86 net send-data zombie guuid=565c52bb-1800-0000-8fa6-7554e70b0000 pid=3047->guuid=d481e5bb-1800-0000-8fa6-7554eb0b0000 pid=3051 clone d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 176.65.139.161:25596 guuid=d481e5bb-1800-0000-8fa6-7554eb0b0000 pid=3051->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 send: 20B guuid=abba8ef7-1800-0000-8fa6-75546b0c0000 pid=3179->72a78419-8065-5ec7-93ba-cdb426fb221b send: 144B guuid=6896683a-1900-0000-8fa6-7554b10c0000 pid=3249->72a78419-8065-5ec7-93ba-cdb426fb221b send: 146B guuid=27a2ab7d-1900-0000-8fa6-75541c0d0000 pid=3356->72a78419-8065-5ec7-93ba-cdb426fb221b send: 143B guuid=9b1a7bbf-1900-0000-8fa6-7554b20d0000 pid=3506->72a78419-8065-5ec7-93ba-cdb426fb221b send: 144B guuid=e75637c9-1900-0000-8fa6-7554c40d0000 pid=3524 /tmp/k.arm7 net send-data zombie guuid=51be24c6-1900-0000-8fa6-7554ba0d0000 pid=3514->guuid=e75637c9-1900-0000-8fa6-7554c40d0000 pid=3524 clone guuid=e75637c9-1900-0000-8fa6-7554c40d0000 pid=3524->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 send: 20B guuid=b16c0b02-1a00-0000-8fa6-7554dc0d0000 pid=3548->72a78419-8065-5ec7-93ba-cdb426fb221b send: 143B guuid=74f15845-1a00-0000-8fa6-7554670e0000 pid=3687->72a78419-8065-5ec7-93ba-cdb426fb221b send: 146B guuid=4909fb51-1a00-0000-8fa6-7554770e0000 pid=3703 /tmp/k.x86_64 net send-data zombie guuid=d9099051-1a00-0000-8fa6-7554750e0000 pid=3701->guuid=4909fb51-1a00-0000-8fa6-7554770e0000 pid=3703 clone guuid=4909fb51-1a00-0000-8fa6-7554770e0000 pid=3703->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 send: 20B
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-05-01 18:33:03 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b7d8c602e19344b7ed2cb6c13e3d4a8a2c3ec4d2106227e73cbe8916a3201f29

(this sample)

  
Delivery method
Distributed via web download

Comments