MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb1d83bf2f3b09d9cd630ab0158b11c0dbced6df36d21a99e0ea723eda3bfd8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: bb1d83bf2f3b09d9cd630ab0158b11c0dbced6df36d21a99e0ea723eda3bfd8c
SHA3-384 hash: 4e4c3b1cddfed63be9e0d85f104b26cf1737e901a13595cf40b46d5cdd6aa4bac4f06d0f566019374071ef549c7fd331
SHA1 hash: a881f16578b30e668fc21409de37fe87d81b72b5
MD5 hash: 2cccd61e533469a19f2a89b89eb0a56a
humanhash: hot-hawaii-lithium-summer
File name:bbcl
Download: download sample
File size:315 bytes
First seen:2026-05-23 01:19:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:h2K6PqhwQLy4IHphUOzNXsmIqwXw81CXD7m+bg6KNXYaF:4Psy4sphD1wXwrXDqiKiaF
TLSH T1C0E0CD9645B3C5F74C594C60E0B33D14E31F647AEF3080606A0395737A8F106B8694B5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=8f21382f-1800-0000-4ff3-88f4610c0000 pid=3169 /usr/bin/sudo guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173 /tmp/sample.bin guuid=8f21382f-1800-0000-4ff3-88f4610c0000 pid=3169->guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173 execve guuid=852b1632-1800-0000-4ff3-88f4660c0000 pid=3174 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=852b1632-1800-0000-4ff3-88f4660c0000 pid=3174 execve guuid=f7f4fc32-1800-0000-4ff3-88f4670c0000 pid=3175 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=f7f4fc32-1800-0000-4ff3-88f4670c0000 pid=3175 execve guuid=87c87f33-1800-0000-4ff3-88f4680c0000 pid=3176 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=87c87f33-1800-0000-4ff3-88f4680c0000 pid=3176 execve guuid=7529d133-1800-0000-4ff3-88f4690c0000 pid=3177 /home/sandbox/gbhnj.arm guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=7529d133-1800-0000-4ff3-88f4690c0000 pid=3177 execve guuid=fa23e635-1800-0000-4ff3-88f46b0c0000 pid=3179 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=fa23e635-1800-0000-4ff3-88f46b0c0000 pid=3179 execve guuid=30aa6536-1800-0000-4ff3-88f46c0c0000 pid=3180 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=30aa6536-1800-0000-4ff3-88f46c0c0000 pid=3180 execve guuid=a94f9436-1800-0000-4ff3-88f46d0c0000 pid=3181 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=a94f9436-1800-0000-4ff3-88f46d0c0000 pid=3181 execve guuid=cba4e036-1800-0000-4ff3-88f46e0c0000 pid=3182 /home/sandbox/gbhnj.arm5 guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=cba4e036-1800-0000-4ff3-88f46e0c0000 pid=3182 execve guuid=164ec337-1800-0000-4ff3-88f4700c0000 pid=3184 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=164ec337-1800-0000-4ff3-88f4700c0000 pid=3184 execve guuid=286f3f38-1800-0000-4ff3-88f4710c0000 pid=3185 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=286f3f38-1800-0000-4ff3-88f4710c0000 pid=3185 execve guuid=d1417038-1800-0000-4ff3-88f4720c0000 pid=3186 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=d1417038-1800-0000-4ff3-88f4720c0000 pid=3186 execve guuid=87fdc338-1800-0000-4ff3-88f4730c0000 pid=3187 /home/sandbox/gbhnj.arm6 guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=87fdc338-1800-0000-4ff3-88f4730c0000 pid=3187 execve guuid=770b9d39-1800-0000-4ff3-88f4750c0000 pid=3189 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=770b9d39-1800-0000-4ff3-88f4750c0000 pid=3189 execve guuid=b2d31f3a-1800-0000-4ff3-88f4760c0000 pid=3190 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=b2d31f3a-1800-0000-4ff3-88f4760c0000 pid=3190 execve guuid=3018593a-1800-0000-4ff3-88f4770c0000 pid=3191 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=3018593a-1800-0000-4ff3-88f4770c0000 pid=3191 execve guuid=02daa93a-1800-0000-4ff3-88f4780c0000 pid=3192 /home/sandbox/gbhnj.arm7 guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=02daa93a-1800-0000-4ff3-88f4780c0000 pid=3192 execve guuid=7150fb3c-1800-0000-4ff3-88f47a0c0000 pid=3194 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=7150fb3c-1800-0000-4ff3-88f47a0c0000 pid=3194 execve guuid=16148d3d-1800-0000-4ff3-88f47b0c0000 pid=3195 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=16148d3d-1800-0000-4ff3-88f47b0c0000 pid=3195 execve guuid=31c7c53d-1800-0000-4ff3-88f47c0c0000 pid=3196 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=31c7c53d-1800-0000-4ff3-88f47c0c0000 pid=3196 execve guuid=3c08443e-1800-0000-4ff3-88f47d0c0000 pid=3197 /home/sandbox/gbhnj.m68k guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=3c08443e-1800-0000-4ff3-88f47d0c0000 pid=3197 execve guuid=ed2a763f-1800-0000-4ff3-88f47f0c0000 pid=3199 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=ed2a763f-1800-0000-4ff3-88f47f0c0000 pid=3199 execve guuid=4fe21640-1800-0000-4ff3-88f4800c0000 pid=3200 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=4fe21640-1800-0000-4ff3-88f4800c0000 pid=3200 execve guuid=87cc5040-1800-0000-4ff3-88f4810c0000 pid=3201 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=87cc5040-1800-0000-4ff3-88f4810c0000 pid=3201 execve guuid=e31daf40-1800-0000-4ff3-88f4820c0000 pid=3202 /home/sandbox/gbhnj.mips guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=e31daf40-1800-0000-4ff3-88f4820c0000 pid=3202 execve guuid=3f6b8a41-1800-0000-4ff3-88f4850c0000 pid=3205 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=3f6b8a41-1800-0000-4ff3-88f4850c0000 pid=3205 execve guuid=b053f041-1800-0000-4ff3-88f4860c0000 pid=3206 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=b053f041-1800-0000-4ff3-88f4860c0000 pid=3206 execve guuid=a32d1c42-1800-0000-4ff3-88f4870c0000 pid=3207 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=a32d1c42-1800-0000-4ff3-88f4870c0000 pid=3207 execve guuid=bced6042-1800-0000-4ff3-88f4880c0000 pid=3208 /home/sandbox/gbhnj.mpsl guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=bced6042-1800-0000-4ff3-88f4880c0000 pid=3208 execve guuid=e3552643-1800-0000-4ff3-88f48a0c0000 pid=3210 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=e3552643-1800-0000-4ff3-88f48a0c0000 pid=3210 execve guuid=5b8d9e43-1800-0000-4ff3-88f48b0c0000 pid=3211 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=5b8d9e43-1800-0000-4ff3-88f48b0c0000 pid=3211 execve guuid=4541c643-1800-0000-4ff3-88f48d0c0000 pid=3213 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=4541c643-1800-0000-4ff3-88f48d0c0000 pid=3213 execve guuid=b804fa43-1800-0000-4ff3-88f48e0c0000 pid=3214 /home/sandbox/gbhnj.ppc guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=b804fa43-1800-0000-4ff3-88f48e0c0000 pid=3214 execve guuid=4df19844-1800-0000-4ff3-88f4930c0000 pid=3219 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=4df19844-1800-0000-4ff3-88f4930c0000 pid=3219 execve guuid=63d6fb44-1800-0000-4ff3-88f4950c0000 pid=3221 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=63d6fb44-1800-0000-4ff3-88f4950c0000 pid=3221 execve guuid=07881f45-1800-0000-4ff3-88f4960c0000 pid=3222 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=07881f45-1800-0000-4ff3-88f4960c0000 pid=3222 execve guuid=d4155445-1800-0000-4ff3-88f4980c0000 pid=3224 /usr/bin/dash guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=d4155445-1800-0000-4ff3-88f4980c0000 pid=3224 clone guuid=121bf545-1800-0000-4ff3-88f49c0c0000 pid=3228 /usr/bin/cp guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=121bf545-1800-0000-4ff3-88f49c0c0000 pid=3228 execve guuid=3c284f46-1800-0000-4ff3-88f49e0c0000 pid=3230 /usr/bin/busybox guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=3c284f46-1800-0000-4ff3-88f49e0c0000 pid=3230 execve guuid=d563b146-1800-0000-4ff3-88f49f0c0000 pid=3231 /usr/bin/chmod guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=d563b146-1800-0000-4ff3-88f49f0c0000 pid=3231 execve guuid=f6553547-1800-0000-4ff3-88f4a20c0000 pid=3234 /home/sandbox/gbhnj.x86_64 guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=f6553547-1800-0000-4ff3-88f4a20c0000 pid=3234 execve guuid=323df748-1800-0000-4ff3-88f4a80c0000 pid=3240 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=323df748-1800-0000-4ff3-88f4a80c0000 pid=3240 execve guuid=a07c3b49-1800-0000-4ff3-88f4aa0c0000 pid=3242 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=a07c3b49-1800-0000-4ff3-88f4aa0c0000 pid=3242 execve guuid=07987549-1800-0000-4ff3-88f4ac0c0000 pid=3244 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=07987549-1800-0000-4ff3-88f4ac0c0000 pid=3244 execve guuid=c0cbb149-1800-0000-4ff3-88f4ad0c0000 pid=3245 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=c0cbb149-1800-0000-4ff3-88f4ad0c0000 pid=3245 execve guuid=a2d5f449-1800-0000-4ff3-88f4af0c0000 pid=3247 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=a2d5f449-1800-0000-4ff3-88f4af0c0000 pid=3247 execve guuid=9867404a-1800-0000-4ff3-88f4b00c0000 pid=3248 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=9867404a-1800-0000-4ff3-88f4b00c0000 pid=3248 execve guuid=e7228c4a-1800-0000-4ff3-88f4b10c0000 pid=3249 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=e7228c4a-1800-0000-4ff3-88f4b10c0000 pid=3249 execve guuid=0a9bcb4a-1800-0000-4ff3-88f4b30c0000 pid=3251 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=0a9bcb4a-1800-0000-4ff3-88f4b30c0000 pid=3251 execve guuid=61ab064b-1800-0000-4ff3-88f4b50c0000 pid=3253 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=61ab064b-1800-0000-4ff3-88f4b50c0000 pid=3253 execve guuid=3628424b-1800-0000-4ff3-88f4b70c0000 pid=3255 /usr/bin/rm delete-file guuid=63fd8531-1800-0000-4ff3-88f4650c0000 pid=3173->guuid=3628424b-1800-0000-4ff3-88f4b70c0000 pid=3255 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2026-05-23 01:21:03 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bb1d83bf2f3b09d9cd630ab0158b11c0dbced6df36d21a99e0ea723eda3bfd8c

(this sample)

  
Delivery method
Distributed via web download

Comments