🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb404c5f48e217cdc5a2f598c4052f228a378ae21e339c874846ec6fccd4c29e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bb404c5f48e217cdc5a2f598c4052f228a378ae21e339c874846ec6fccd4c29e
SHA3-384 hash: 40115558d16dc9b838de1ea96186dfbc694cde080ccec0240dcc455a2401865fa66728a2f2a1e136d8407118e03d9789
SHA1 hash: 928e3d8487b619064e97e4e2eb8befccbadc2bbe
MD5 hash: 066df21b7180f7e664520a92bd9acaef
humanhash: neptune-single-twenty-sixteen
File name:bb404c5f48e217cdc5a2f598c4052f228a378ae21e339c874846ec6fccd4c29e
Download: download sample
File size:8'747 bytes
First seen:2026-09-09 10:00:20 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:wFSIDVI8Ub7Y4/qjsvlzO78tfBmvTEGq52EXqbsJ:rIDVPmYjsvlzO78tfBI4Gq5nXqbC
TLSH T1AA0221B1B404667135A9C02C97FAD0025951713735546C18B9AEF9347FFC346B3B8BBA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.73.4.32:8008/install.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
18
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Status:
terminated
Behavior Graph:
%3 guuid=91e4e637-1b00-0000-d089-b0f6f10a0000 pid=2801 /usr/bin/sudo guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809 /tmp/sample.bin guuid=91e4e637-1b00-0000-d089-b0f6f10a0000 pid=2801->guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809 execve guuid=e5abe440-1b00-0000-d089-b0f6fa0a0000 pid=2810 /usr/bin/dash guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809->guuid=e5abe440-1b00-0000-d089-b0f6fa0a0000 pid=2810 clone guuid=e5957949-1b00-0000-d089-b0f6ff0a0000 pid=2815 /usr/bin/dash guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809->guuid=e5957949-1b00-0000-d089-b0f6ff0a0000 pid=2815 clone guuid=c2308b49-1b00-0000-d089-b0f6000b0000 pid=2816 /usr/bin/wget net guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809->guuid=c2308b49-1b00-0000-d089-b0f6000b0000 pid=2816 execve guuid=ea40de5c-1b00-0000-d089-b0f60b0b0000 pid=2827 /usr/bin/wget net guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809->guuid=ea40de5c-1b00-0000-d089-b0f60b0b0000 pid=2827 execve guuid=3fcd8a6b-1b00-0000-d089-b0f61e0b0000 pid=2846 /usr/bin/rm delete-file guuid=1b74f23f-1b00-0000-d089-b0f6f90a0000 pid=2809->guuid=3fcd8a6b-1b00-0000-d089-b0f61e0b0000 pid=2846 execve guuid=5135a943-1b00-0000-d089-b0f6fb0a0000 pid=2811 /usr/bin/uname guuid=e5abe440-1b00-0000-d089-b0f6fa0a0000 pid=2810->guuid=5135a943-1b00-0000-d089-b0f6fb0a0000 pid=2811 execve guuid=26e53447-1b00-0000-d089-b0f6fc0a0000 pid=2812 /usr/bin/dash guuid=e5abe440-1b00-0000-d089-b0f6fa0a0000 pid=2810->guuid=26e53447-1b00-0000-d089-b0f6fc0a0000 pid=2812 clone guuid=582a4547-1b00-0000-d089-b0f6fd0a0000 pid=2813 /usr/bin/dash guuid=26e53447-1b00-0000-d089-b0f6fc0a0000 pid=2812->guuid=582a4547-1b00-0000-d089-b0f6fd0a0000 pid=2813 clone guuid=bbf75447-1b00-0000-d089-b0f6fe0a0000 pid=2814 /usr/bin/tr guuid=26e53447-1b00-0000-d089-b0f6fc0a0000 pid=2812->guuid=bbf75447-1b00-0000-d089-b0f6fe0a0000 pid=2814 execve 125dc6e8-b5eb-56d4-939d-3c8afb78f6f0 202.73.4.32:8008 guuid=c2308b49-1b00-0000-d089-b0f6000b0000 pid=2816->125dc6e8-b5eb-56d4-939d-3c8afb78f6f0 con guuid=ea40de5c-1b00-0000-d089-b0f60b0b0000 pid=2827->125dc6e8-b5eb-56d4-939d-3c8afb78f6f0 con
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments