🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9f33ec7975260a08cefb2604a39f1e52e84ebada9fc07c3a39a5e4fd75d933e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b9f33ec7975260a08cefb2604a39f1e52e84ebada9fc07c3a39a5e4fd75d933e
SHA3-384 hash: 404535a7cbc63b5fbc9e9ca5bddaa19e65dedd5cad26910bb530748989158e05e77eaf15e7ae0560e336184a3e3587ee
SHA1 hash: bf5315e64df631e3c3d703140add7de5ff2889e9
MD5 hash: 13c0c457be26c386bc46c17498132776
humanhash: queen-summer-louisiana-avocado
File name:drop-simple.sh
Download: download sample
File size:1'729 bytes
First seen:2026-09-27 06:38:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:EVACIpROpRegqNR2/zXuXi/2Vqlf5DMRYLThNeLzYJZ7NeL/o7RwhAxNhAnfy:8Ka9/Lt/2VqrDMCNeXYJZ7NeL/Et8q
TLSH T19E310F9172600271F36DCF2A169B48B9904F622785149A1CF1DE8D7421F4BE2F1F6BA4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
CZ CZ
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
unix shell
First seen:
2026-09-27T03:54:00Z UTC
Last seen:
2026-09-28T19:37:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=223268c5-1800-0000-03b6-d0fdfa0b0000 pid=3066 /usr/bin/sudo guuid=f7e03cc9-1800-0000-03b6-d0fd040c0000 pid=3076 /tmp/sample.bin guuid=223268c5-1800-0000-03b6-d0fdfa0b0000 pid=3066->guuid=f7e03cc9-1800-0000-03b6-d0fd040c0000 pid=3076 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-27 06:39:09 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments