MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b98e554dd386c73ed7b2cc37f9f2bc96d293a6193da3f83ca5194b48b14be2f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b98e554dd386c73ed7b2cc37f9f2bc96d293a6193da3f83ca5194b48b14be2f1
SHA3-384 hash: e0efc0402a6222d13c5919f4fb4dd85a5e99cce1cf4b815c16e9221da17711d06a0f2b85b6ea3cf17fe7268d85c00f41
SHA1 hash: c264a54849d184e255cfd7c78c527a0c02771450
MD5 hash: bd9eadbf1fc9010c94a9941f41094647
humanhash: march-salami-one-green
File name:run.sh
Download: download sample
File size:3'141 bytes
First seen:2026-01-20 19:13:50 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:Cb2JMqsbiBKjuZFEUEnE2EhEGUObwLOJUf92hM3e:Cb2JMqsbiBKjuZFFcvyiObwb2hM3e
TLSH T1B15188B6023F86B27208924DB3FD3639A28770936BEE4A01AD603C1D2EC5D0C63D4F80
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-01-20T16:21:00Z UTC
Last seen:
2026-01-20T16:45:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=672a0c29-1c00-0000-0cf3-5a9be50c0000 pid=3301 /usr/bin/sudo guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307 /tmp/sample.bin guuid=672a0c29-1c00-0000-0cf3-5a9be50c0000 pid=3301->guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307 execve guuid=128bf82b-1c00-0000-0cf3-5a9bee0c0000 pid=3310 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=128bf82b-1c00-0000-0cf3-5a9bee0c0000 pid=3310 execve guuid=5a677430-1c00-0000-0cf3-5a9bf60c0000 pid=3318 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=5a677430-1c00-0000-0cf3-5a9bf60c0000 pid=3318 execve guuid=ddebe038-1c00-0000-0cf3-5a9bfd0c0000 pid=3325 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=ddebe038-1c00-0000-0cf3-5a9bfd0c0000 pid=3325 execve guuid=3b943739-1c00-0000-0cf3-5a9bfe0c0000 pid=3326 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=3b943739-1c00-0000-0cf3-5a9bfe0c0000 pid=3326 clone guuid=614d4e39-1c00-0000-0cf3-5a9bff0c0000 pid=3327 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=614d4e39-1c00-0000-0cf3-5a9bff0c0000 pid=3327 execve guuid=8208df39-1c00-0000-0cf3-5a9b000d0000 pid=3328 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=8208df39-1c00-0000-0cf3-5a9b000d0000 pid=3328 execve guuid=7e290d3b-1c00-0000-0cf3-5a9b010d0000 pid=3329 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=7e290d3b-1c00-0000-0cf3-5a9b010d0000 pid=3329 execve guuid=2b31903d-1c00-0000-0cf3-5a9b020d0000 pid=3330 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=2b31903d-1c00-0000-0cf3-5a9b020d0000 pid=3330 execve guuid=2c22343e-1c00-0000-0cf3-5a9b030d0000 pid=3331 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=2c22343e-1c00-0000-0cf3-5a9b030d0000 pid=3331 clone guuid=7c654a3e-1c00-0000-0cf3-5a9b040d0000 pid=3332 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=7c654a3e-1c00-0000-0cf3-5a9b040d0000 pid=3332 execve guuid=9f68c13e-1c00-0000-0cf3-5a9b050d0000 pid=3333 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=9f68c13e-1c00-0000-0cf3-5a9b050d0000 pid=3333 execve guuid=922b1440-1c00-0000-0cf3-5a9b060d0000 pid=3334 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=922b1440-1c00-0000-0cf3-5a9b060d0000 pid=3334 execve guuid=ef40df41-1c00-0000-0cf3-5a9b080d0000 pid=3336 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=ef40df41-1c00-0000-0cf3-5a9b080d0000 pid=3336 execve guuid=648a2842-1c00-0000-0cf3-5a9b090d0000 pid=3337 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=648a2842-1c00-0000-0cf3-5a9b090d0000 pid=3337 clone guuid=a9ca3442-1c00-0000-0cf3-5a9b0b0d0000 pid=3339 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=a9ca3442-1c00-0000-0cf3-5a9b0b0d0000 pid=3339 execve guuid=7cf27742-1c00-0000-0cf3-5a9b0c0d0000 pid=3340 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=7cf27742-1c00-0000-0cf3-5a9b0c0d0000 pid=3340 execve guuid=4f963843-1c00-0000-0cf3-5a9b0f0d0000 pid=3343 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=4f963843-1c00-0000-0cf3-5a9b0f0d0000 pid=3343 execve guuid=e0fbc044-1c00-0000-0cf3-5a9b140d0000 pid=3348 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=e0fbc044-1c00-0000-0cf3-5a9b140d0000 pid=3348 execve guuid=a7560845-1c00-0000-0cf3-5a9b150d0000 pid=3349 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=a7560845-1c00-0000-0cf3-5a9b150d0000 pid=3349 clone guuid=ac0c2145-1c00-0000-0cf3-5a9b170d0000 pid=3351 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=ac0c2145-1c00-0000-0cf3-5a9b170d0000 pid=3351 execve guuid=2d936c45-1c00-0000-0cf3-5a9b180d0000 pid=3352 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=2d936c45-1c00-0000-0cf3-5a9b180d0000 pid=3352 execve guuid=01fb4346-1c00-0000-0cf3-5a9b1b0d0000 pid=3355 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=01fb4346-1c00-0000-0cf3-5a9b1b0d0000 pid=3355 execve guuid=62cbb949-1c00-0000-0cf3-5a9b230d0000 pid=3363 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=62cbb949-1c00-0000-0cf3-5a9b230d0000 pid=3363 execve guuid=a8bb004a-1c00-0000-0cf3-5a9b250d0000 pid=3365 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=a8bb004a-1c00-0000-0cf3-5a9b250d0000 pid=3365 clone guuid=216a124a-1c00-0000-0cf3-5a9b260d0000 pid=3366 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=216a124a-1c00-0000-0cf3-5a9b260d0000 pid=3366 execve guuid=4519644a-1c00-0000-0cf3-5a9b270d0000 pid=3367 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=4519644a-1c00-0000-0cf3-5a9b270d0000 pid=3367 execve guuid=a9f2414b-1c00-0000-0cf3-5a9b2a0d0000 pid=3370 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=a9f2414b-1c00-0000-0cf3-5a9b2a0d0000 pid=3370 execve guuid=a0fada4c-1c00-0000-0cf3-5a9b2f0d0000 pid=3375 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=a0fada4c-1c00-0000-0cf3-5a9b2f0d0000 pid=3375 execve guuid=025d294d-1c00-0000-0cf3-5a9b310d0000 pid=3377 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=025d294d-1c00-0000-0cf3-5a9b310d0000 pid=3377 clone guuid=80b5354d-1c00-0000-0cf3-5a9b320d0000 pid=3378 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=80b5354d-1c00-0000-0cf3-5a9b320d0000 pid=3378 execve guuid=f024794d-1c00-0000-0cf3-5a9b330d0000 pid=3379 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=f024794d-1c00-0000-0cf3-5a9b330d0000 pid=3379 execve guuid=406d324e-1c00-0000-0cf3-5a9b360d0000 pid=3382 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=406d324e-1c00-0000-0cf3-5a9b360d0000 pid=3382 execve guuid=8a9b0854-1c00-0000-0cf3-5a9b450d0000 pid=3397 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=8a9b0854-1c00-0000-0cf3-5a9b450d0000 pid=3397 execve guuid=4d344e54-1c00-0000-0cf3-5a9b470d0000 pid=3399 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=4d344e54-1c00-0000-0cf3-5a9b470d0000 pid=3399 clone guuid=00e06254-1c00-0000-0cf3-5a9b480d0000 pid=3400 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=00e06254-1c00-0000-0cf3-5a9b480d0000 pid=3400 execve guuid=66449e54-1c00-0000-0cf3-5a9b4a0d0000 pid=3402 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=66449e54-1c00-0000-0cf3-5a9b4a0d0000 pid=3402 execve guuid=60ba4b55-1c00-0000-0cf3-5a9b4d0d0000 pid=3405 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=60ba4b55-1c00-0000-0cf3-5a9b4d0d0000 pid=3405 execve guuid=9e8a3158-1c00-0000-0cf3-5a9b550d0000 pid=3413 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=9e8a3158-1c00-0000-0cf3-5a9b550d0000 pid=3413 execve guuid=a8947958-1c00-0000-0cf3-5a9b570d0000 pid=3415 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=a8947958-1c00-0000-0cf3-5a9b570d0000 pid=3415 clone guuid=c6d88958-1c00-0000-0cf3-5a9b580d0000 pid=3416 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=c6d88958-1c00-0000-0cf3-5a9b580d0000 pid=3416 execve guuid=5c1bcc58-1c00-0000-0cf3-5a9b590d0000 pid=3417 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=5c1bcc58-1c00-0000-0cf3-5a9b590d0000 pid=3417 execve guuid=cfaba759-1c00-0000-0cf3-5a9b5d0d0000 pid=3421 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=cfaba759-1c00-0000-0cf3-5a9b5d0d0000 pid=3421 execve guuid=324f985b-1c00-0000-0cf3-5a9b620d0000 pid=3426 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=324f985b-1c00-0000-0cf3-5a9b620d0000 pid=3426 execve guuid=06a0d65b-1c00-0000-0cf3-5a9b630d0000 pid=3427 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=06a0d65b-1c00-0000-0cf3-5a9b630d0000 pid=3427 clone guuid=986fe65b-1c00-0000-0cf3-5a9b650d0000 pid=3429 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=986fe65b-1c00-0000-0cf3-5a9b650d0000 pid=3429 execve guuid=29c7405c-1c00-0000-0cf3-5a9b660d0000 pid=3430 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=29c7405c-1c00-0000-0cf3-5a9b660d0000 pid=3430 execve guuid=7c5e5b5d-1c00-0000-0cf3-5a9b6a0d0000 pid=3434 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=7c5e5b5d-1c00-0000-0cf3-5a9b6a0d0000 pid=3434 execve guuid=5bcdc55f-1c00-0000-0cf3-5a9b710d0000 pid=3441 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=5bcdc55f-1c00-0000-0cf3-5a9b710d0000 pid=3441 execve guuid=144d3160-1c00-0000-0cf3-5a9b730d0000 pid=3443 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=144d3160-1c00-0000-0cf3-5a9b730d0000 pid=3443 clone guuid=d6014460-1c00-0000-0cf3-5a9b740d0000 pid=3444 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=d6014460-1c00-0000-0cf3-5a9b740d0000 pid=3444 execve guuid=14929360-1c00-0000-0cf3-5a9b760d0000 pid=3446 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=14929360-1c00-0000-0cf3-5a9b760d0000 pid=3446 execve guuid=3c9ec561-1c00-0000-0cf3-5a9b7b0d0000 pid=3451 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=3c9ec561-1c00-0000-0cf3-5a9b7b0d0000 pid=3451 execve guuid=1862fe63-1c00-0000-0cf3-5a9b820d0000 pid=3458 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=1862fe63-1c00-0000-0cf3-5a9b820d0000 pid=3458 execve guuid=76064864-1c00-0000-0cf3-5a9b840d0000 pid=3460 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=76064864-1c00-0000-0cf3-5a9b840d0000 pid=3460 clone guuid=c7086a64-1c00-0000-0cf3-5a9b860d0000 pid=3462 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=c7086a64-1c00-0000-0cf3-5a9b860d0000 pid=3462 execve guuid=2f4ec864-1c00-0000-0cf3-5a9b880d0000 pid=3464 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=2f4ec864-1c00-0000-0cf3-5a9b880d0000 pid=3464 execve guuid=3cbeb065-1c00-0000-0cf3-5a9b8b0d0000 pid=3467 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=3cbeb065-1c00-0000-0cf3-5a9b8b0d0000 pid=3467 execve guuid=eae51e68-1c00-0000-0cf3-5a9b930d0000 pid=3475 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=eae51e68-1c00-0000-0cf3-5a9b930d0000 pid=3475 execve guuid=330c5e68-1c00-0000-0cf3-5a9b950d0000 pid=3477 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=330c5e68-1c00-0000-0cf3-5a9b950d0000 pid=3477 clone guuid=2f846e68-1c00-0000-0cf3-5a9b960d0000 pid=3478 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=2f846e68-1c00-0000-0cf3-5a9b960d0000 pid=3478 execve guuid=267dc368-1c00-0000-0cf3-5a9b980d0000 pid=3480 /usr/bin/wget guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=267dc368-1c00-0000-0cf3-5a9b980d0000 pid=3480 execve guuid=f5069d69-1c00-0000-0cf3-5a9b9b0d0000 pid=3483 /usr/bin/curl guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=f5069d69-1c00-0000-0cf3-5a9b9b0d0000 pid=3483 execve guuid=7d26da6c-1c00-0000-0cf3-5a9ba50d0000 pid=3493 /usr/bin/chmod guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=7d26da6c-1c00-0000-0cf3-5a9ba50d0000 pid=3493 execve guuid=f170286d-1c00-0000-0cf3-5a9ba60d0000 pid=3494 /usr/bin/dash guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=f170286d-1c00-0000-0cf3-5a9ba60d0000 pid=3494 clone guuid=b8303c6d-1c00-0000-0cf3-5a9ba80d0000 pid=3496 /usr/bin/rm guuid=caf09a2b-1c00-0000-0cf3-5a9beb0c0000 pid=3307->guuid=b8303c6d-1c00-0000-0cf3-5a9ba80d0000 pid=3496 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2026-01-20 19:16:07 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b98e554dd386c73ed7b2cc37f9f2bc96d293a6193da3f83ca5194b48b14be2f1

(this sample)

  
Delivery method
Distributed via web download

Comments