MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bbd7ec5557567974e343e8987be3bc5c1276162198b9d40f94da43b3acc49ea5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bbd7ec5557567974e343e8987be3bc5c1276162198b9d40f94da43b3acc49ea5
SHA3-384 hash: 8398c3fc74dd71ef4214b5f8cfa7db66f67ccfd43ff2cc9fb1d6012fcddaf0a8e24560d5176922bb24a01bbf99630388
SHA1 hash: 928969831a817b0bc8b29b352f34f5dae8da21ac
MD5 hash: e6bb454800ab5c77df03ad1a87c6d4ba
humanhash: tango-oscar-oven-victor
File name:bins.sh
Download: download sample
File size:273 bytes
First seen:2026-04-09 22:07:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:h/qVzB+QFnTAJ3lqLeBsA+fW4UfpzfW4U5plVyQJfRX5K:5HQFn8J3lf0fgfpzfGpT1ta
TLSH T190D02B916491503399CCC45B6995D09D308130032C46752CA43376364BCC198F0A5FF8
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
unknown
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=051a877e-1900-0000-8c7f-a538880b0000 pid=2952 /usr/bin/sudo guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958 /tmp/sample.bin guuid=051a877e-1900-0000-8c7f-a538880b0000 pid=2952->guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958 execve guuid=b86d8880-1900-0000-8c7f-a5388f0b0000 pid=2959 /usr/bin/wget net send-data write-file guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=b86d8880-1900-0000-8c7f-a5388f0b0000 pid=2959 execve guuid=45cce647-1a00-0000-8c7f-a538a60c0000 pid=3238 /usr/bin/chmod guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=45cce647-1a00-0000-8c7f-a538a60c0000 pid=3238 execve guuid=af1b9d48-1a00-0000-8c7f-a538a80c0000 pid=3240 /usr/bin/dash guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=af1b9d48-1a00-0000-8c7f-a538a80c0000 pid=3240 clone guuid=53c19649-1a00-0000-8c7f-a538ac0c0000 pid=3244 /usr/bin/wget net send-data write-file guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=53c19649-1a00-0000-8c7f-a538ac0c0000 pid=3244 execve guuid=26b8dafe-1a00-0000-8c7f-a538cb0d0000 pid=3531 /usr/bin/chmod guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=26b8dafe-1a00-0000-8c7f-a538cb0d0000 pid=3531 execve guuid=ad744cff-1a00-0000-8c7f-a538cd0d0000 pid=3533 /usr/bin/dash guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=ad744cff-1a00-0000-8c7f-a538cd0d0000 pid=3533 clone guuid=de33c900-1b00-0000-8c7f-a538d30d0000 pid=3539 /usr/bin/wget net send-data write-file guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=de33c900-1b00-0000-8c7f-a538d30d0000 pid=3539 execve guuid=7adfbd15-1b00-0000-8c7f-a538060e0000 pid=3590 /usr/bin/chmod guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=7adfbd15-1b00-0000-8c7f-a538060e0000 pid=3590 execve guuid=341f2716-1b00-0000-8c7f-a538080e0000 pid=3592 /usr/bin/dash guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=341f2716-1b00-0000-8c7f-a538080e0000 pid=3592 clone guuid=309c0017-1b00-0000-8c7f-a5380c0e0000 pid=3596 /usr/bin/wget net send-data write-file guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=309c0017-1b00-0000-8c7f-a5380c0e0000 pid=3596 execve guuid=39f11a29-1b00-0000-8c7f-a538300e0000 pid=3632 /usr/bin/chmod guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=39f11a29-1b00-0000-8c7f-a538300e0000 pid=3632 execve guuid=ec556629-1b00-0000-8c7f-a538340e0000 pid=3636 /usr/bin/dash guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=ec556629-1b00-0000-8c7f-a538340e0000 pid=3636 clone guuid=05cbfc29-1b00-0000-8c7f-a538390e0000 pid=3641 /usr/bin/wget net send-data write-file guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=05cbfc29-1b00-0000-8c7f-a538390e0000 pid=3641 execve guuid=4fa36c37-1b00-0000-8c7f-a5385c0e0000 pid=3676 /usr/bin/chmod guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=4fa36c37-1b00-0000-8c7f-a5385c0e0000 pid=3676 execve guuid=d2c8df37-1b00-0000-8c7f-a5385d0e0000 pid=3677 /tmp/x86 dns net send-data guuid=513e5180-1900-0000-8c7f-a5388e0b0000 pid=2958->guuid=d2c8df37-1b00-0000-8c7f-a5385d0e0000 pid=3677 execve 6c41c2cd-8068-525f-9229-995adab0aeae 176.65.139.67:80 guuid=b86d8880-1900-0000-8c7f-a5388f0b0000 pid=2959->6c41c2cd-8068-525f-9229-995adab0aeae send: 131B guuid=53c19649-1a00-0000-8c7f-a538ac0c0000 pid=3244->6c41c2cd-8068-525f-9229-995adab0aeae send: 132B guuid=de33c900-1b00-0000-8c7f-a538d30d0000 pid=3539->6c41c2cd-8068-525f-9229-995adab0aeae send: 132B guuid=309c0017-1b00-0000-8c7f-a5380c0e0000 pid=3596->6c41c2cd-8068-525f-9229-995adab0aeae send: 132B guuid=05cbfc29-1b00-0000-8c7f-a538390e0000 pid=3641->6c41c2cd-8068-525f-9229-995adab0aeae send: 131B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d2c8df37-1b00-0000-8c7f-a5385d0e0000 pid=3677->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 997a677b-e2e3-587d-b712-9bb3900e9b02 51.158.108.203:53 guuid=d2c8df37-1b00-0000-8c7f-a5385d0e0000 pid=3677->997a677b-e2e3-587d-b712-9bb3900e9b02 send: 27B 315d4f61-2c97-504c-bcc1-76e61a3a22eb nordvm.cc:35342 guuid=d2c8df37-1b00-0000-8c7f-a5385d0e0000 pid=3677->315d4f61-2c97-504c-bcc1-76e61a3a22eb send: 37B
Threat name:
Script-Shell.Hacktool.MiraiB
Status:
Malicious
First seen:
2026-04-09 22:07:28 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bbd7ec5557567974e343e8987be3bc5c1276162198b9d40f94da43b3acc49ea5

(this sample)

  
Delivery method
Distributed via web download

Comments