🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bcc4310318fc723f94cea80aaf2e4acdadea223670d1ef420494aad46e051dcc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: bcc4310318fc723f94cea80aaf2e4acdadea223670d1ef420494aad46e051dcc
SHA3-384 hash: 7f596abc56a73fdd5e565f7e57a2e4fad60d9900399ed171af7e697c4c07a906fee2681fcdc31da00c18796169567b43
SHA1 hash: ab444742a2e884d4f6617a07daef36952e6dc5ac
MD5 hash: 6e458298a1de0b53a7596d000dee5cd8
humanhash: twenty-zebra-hotel-glucose
File name:run.sh
Download: download sample
File size:1'359 bytes
First seen:2026-10-05 16:34:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:MD4O2Hsn9NIEZ8s6iSecy9fRVsSe7r3mK6N7gJCkK6+j:MD4/a3IESlyCS8zmrN7Nkrq
TLSH T11021ADE5FA708C63F1CF502CAC5614018BCF4D2B47181E56748F6818777CE1AB456731
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
SK SK
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-05T15:09:00Z UTC
Last seen:
2026-10-06T19:47:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a060910a-1700-0000-2ad5-17b3db0d0000 pid=3547 /usr/bin/sudo guuid=df28eb0d-1700-0000-2ad5-17b3e20d0000 pid=3554 /tmp/sample.bin guuid=a060910a-1700-0000-2ad5-17b3db0d0000 pid=3547->guuid=df28eb0d-1700-0000-2ad5-17b3e20d0000 pid=3554 execve guuid=661cac0e-1700-0000-2ad5-17b3e60d0000 pid=3558 /usr/bin/dash guuid=df28eb0d-1700-0000-2ad5-17b3e20d0000 pid=3554->guuid=661cac0e-1700-0000-2ad5-17b3e60d0000 pid=3558 clone guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3565 /usr/bin/curl net send-data write-file guuid=df28eb0d-1700-0000-2ad5-17b3e20d0000 pid=3554->guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3565 execve guuid=e129fc28-1700-0000-2ad5-17b3390e0000 pid=3641 /usr/bin/chmod guuid=df28eb0d-1700-0000-2ad5-17b3e20d0000 pid=3554->guuid=e129fc28-1700-0000-2ad5-17b3390e0000 pid=3641 execve guuid=18cd5429-1700-0000-2ad5-17b33b0e0000 pid=3643 /usr/bin/dash guuid=df28eb0d-1700-0000-2ad5-17b3e20d0000 pid=3554->guuid=18cd5429-1700-0000-2ad5-17b33b0e0000 pid=3643 clone guuid=2d50f70e-1700-0000-2ad5-17b3e70d0000 pid=3559 /usr/bin/uname guuid=661cac0e-1700-0000-2ad5-17b3e60d0000 pid=3558->guuid=2d50f70e-1700-0000-2ad5-17b3e70d0000 pid=3559 execve guuid=5e86fd0e-1700-0000-2ad5-17b3e80d0000 pid=3560 /usr/bin/tr guuid=661cac0e-1700-0000-2ad5-17b3e60d0000 pid=3558->guuid=5e86fd0e-1700-0000-2ad5-17b3e80d0000 pid=3560 execve e9d72c55-f82d-5cf9-b7db-230c048f35a3 pingl.vip:80 guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3565->e9d72c55-f82d-5cf9-b7db-230c048f35a3 send: 78B guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3575 /usr/bin/curl dns net send-data guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3565->guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3575 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=3f747e10-1700-0000-2ad5-17b3ed0d0000 pid=3575->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 54B guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644 /dev/shm/.amd64_3554 zombie guuid=18cd5429-1700-0000-2ad5-17b33b0e0000 pid=3643->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644 execve guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3668 /dev/shm/.amd64_3554 zombie guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3668 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3670 /dev/shm/.amd64_3554 guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3670 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3671 /dev/shm/.amd64_3554 guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3671 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3672 /dev/shm/.amd64_3554 send-data zombie guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3672 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3674 /dev/shm/.amd64_3554 guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3674 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3675 /dev/shm/.amd64_3554 dns net send-data zombie guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3675 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3676 /dev/shm/.amd64_3554 dns net send-data zombie guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3676 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3683 /dev/shm/.amd64_3554 zombie guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3683 clone guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=5162 /dev/shm/.amd64_3554 guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3644->guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=5162 clone 73264a63-6404-54d8-b598-0c5ff0a49cab pingl.vip:9111 guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3672->73264a63-6404-54d8-b598-0c5ff0a49cab send: 1B guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3675->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3675->73264a63-6404-54d8-b598-0c5ff0a49cab send: 2B guuid=2fbb5a29-1700-0000-2ad5-17b33c0e0000 pid=3676->73264a63-6404-54d8-b598-0c5ff0a49cab send: 23B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-05 16:34:03 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Changes its process name
Checks CPU configuration
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments