MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bedecb838890d650c0e90334d2110251089d7d661c26f17179d90763b99ccd14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bedecb838890d650c0e90334d2110251089d7d661c26f17179d90763b99ccd14
SHA3-384 hash: 713559ddfe2d398a79b1317f4f2dd4d61456a9b05a6500ff4692b9c911f8359365f5a4a91c347e12cb6ffd654666f7c1
SHA1 hash: 94ce12c88011c146b2ff9e533d46194fc7add34f
MD5 hash: 0fa5caf302a4d6cf2b1e6b75df950d03
humanhash: queen-missouri-don-east
File name:build.sh
Download: download sample
File size:2'811 bytes
First seen:2025-12-27 16:52:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:A2AuwpKXg5YyHvIu7eUYBzMKZfT+8DbmW4TVqTIbHyF2dxEESm6cq10kTdrRq:A2vwpKXg5YyHv37eU6RZL+8H14TVk2Hf
TLSH T11251E43A724D7D43405308E32F7EB35BA3A6E0FE3F250D998027A6538A67AD91027579
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Clean
File Type:
unix shell
First seen:
2025-12-27T14:02:00Z UTC
Last seen:
2025-12-27T14:55:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=9f128dcc-1600-0000-0287-3aded60c0000 pid=3286 /usr/bin/sudo guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290 /tmp/sample.bin guuid=9f128dcc-1600-0000-0287-3aded60c0000 pid=3286->guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290 execve guuid=bbe19ace-1600-0000-0287-3adedc0c0000 pid=3292 /usr/bin/rm guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=bbe19ace-1600-0000-0287-3adedc0c0000 pid=3292 execve guuid=90c836cf-1600-0000-0287-3adedd0c0000 pid=3293 /usr/bin/mkdir guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=90c836cf-1600-0000-0287-3adedd0c0000 pid=3293 execve guuid=985edbcf-1600-0000-0287-3adede0c0000 pid=3294 /usr/bin/rm guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=985edbcf-1600-0000-0287-3adede0c0000 pid=3294 execve guuid=b8683cd0-1600-0000-0287-3adedf0c0000 pid=3295 /usr/bin/rm guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=b8683cd0-1600-0000-0287-3adedf0c0000 pid=3295 execve guuid=da5c8ad0-1600-0000-0287-3adee10c0000 pid=3297 /usr/bin/rm guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=da5c8ad0-1600-0000-0287-3adee10c0000 pid=3297 execve guuid=75d0cfd0-1600-0000-0287-3adee30c0000 pid=3299 /usr/bin/mkdir guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=75d0cfd0-1600-0000-0287-3adee30c0000 pid=3299 execve guuid=dfa31dd1-1600-0000-0287-3adee50c0000 pid=3301 /usr/bin/mkdir guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=dfa31dd1-1600-0000-0287-3adee50c0000 pid=3301 execve guuid=d5cc68d1-1600-0000-0287-3adee70c0000 pid=3303 /usr/bin/mkdir guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=d5cc68d1-1600-0000-0287-3adee70c0000 pid=3303 execve guuid=5847b6d1-1600-0000-0287-3adee90c0000 pid=3305 /usr/bin/mkdir guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=5847b6d1-1600-0000-0287-3adee90c0000 pid=3305 execve guuid=7cb20ad2-1600-0000-0287-3adeec0c0000 pid=3308 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=7cb20ad2-1600-0000-0287-3adeec0c0000 pid=3308 clone guuid=b59f20d2-1600-0000-0287-3adeed0c0000 pid=3309 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=b59f20d2-1600-0000-0287-3adeed0c0000 pid=3309 clone guuid=ee703bd2-1600-0000-0287-3adeee0c0000 pid=3310 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=ee703bd2-1600-0000-0287-3adeee0c0000 pid=3310 clone guuid=6a0a55d2-1600-0000-0287-3adef00c0000 pid=3312 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=6a0a55d2-1600-0000-0287-3adef00c0000 pid=3312 clone guuid=cb286dd2-1600-0000-0287-3adef10c0000 pid=3313 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=cb286dd2-1600-0000-0287-3adef10c0000 pid=3313 clone guuid=56848ad2-1600-0000-0287-3adef20c0000 pid=3314 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=56848ad2-1600-0000-0287-3adef20c0000 pid=3314 clone guuid=5f97a9d2-1600-0000-0287-3adef30c0000 pid=3315 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=5f97a9d2-1600-0000-0287-3adef30c0000 pid=3315 clone guuid=c5d2c4d2-1600-0000-0287-3adef50c0000 pid=3317 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=c5d2c4d2-1600-0000-0287-3adef50c0000 pid=3317 clone guuid=d586e4d2-1600-0000-0287-3adef60c0000 pid=3318 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=d586e4d2-1600-0000-0287-3adef60c0000 pid=3318 clone guuid=48ff06d3-1600-0000-0287-3adef80c0000 pid=3320 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=48ff06d3-1600-0000-0287-3adef80c0000 pid=3320 clone guuid=fbfd2ed3-1600-0000-0287-3adef90c0000 pid=3321 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=fbfd2ed3-1600-0000-0287-3adef90c0000 pid=3321 clone guuid=c6914cd3-1600-0000-0287-3adefb0c0000 pid=3323 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=c6914cd3-1600-0000-0287-3adefb0c0000 pid=3323 clone guuid=adac69d3-1600-0000-0287-3adefc0c0000 pid=3324 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=adac69d3-1600-0000-0287-3adefc0c0000 pid=3324 clone guuid=ddf28bd3-1600-0000-0287-3adefe0c0000 pid=3326 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=ddf28bd3-1600-0000-0287-3adefe0c0000 pid=3326 clone guuid=9dd9bed3-1600-0000-0287-3ade000d0000 pid=3328 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=9dd9bed3-1600-0000-0287-3ade000d0000 pid=3328 clone guuid=8165e0d3-1600-0000-0287-3ade010d0000 pid=3329 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=8165e0d3-1600-0000-0287-3ade010d0000 pid=3329 clone guuid=4ae4fed3-1600-0000-0287-3ade030d0000 pid=3331 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=4ae4fed3-1600-0000-0287-3ade030d0000 pid=3331 clone guuid=8b9335d4-1600-0000-0287-3ade040d0000 pid=3332 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=8b9335d4-1600-0000-0287-3ade040d0000 pid=3332 clone guuid=b85e48d4-1600-0000-0287-3ade060d0000 pid=3334 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=b85e48d4-1600-0000-0287-3ade060d0000 pid=3334 clone guuid=f07f61d4-1600-0000-0287-3ade070d0000 pid=3335 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=f07f61d4-1600-0000-0287-3ade070d0000 pid=3335 clone guuid=f92578d4-1600-0000-0287-3ade080d0000 pid=3336 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=f92578d4-1600-0000-0287-3ade080d0000 pid=3336 clone guuid=1bb29dd4-1600-0000-0287-3ade0a0d0000 pid=3338 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=1bb29dd4-1600-0000-0287-3ade0a0d0000 pid=3338 clone guuid=2b66bdd4-1600-0000-0287-3ade0b0d0000 pid=3339 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=2b66bdd4-1600-0000-0287-3ade0b0d0000 pid=3339 clone guuid=0479ddd4-1600-0000-0287-3ade0d0d0000 pid=3341 /usr/bin/bash guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=0479ddd4-1600-0000-0287-3ade0d0d0000 pid=3341 clone guuid=a373fbd4-1600-0000-0287-3ade0e0d0000 pid=3342 /usr/bin/cp guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=a373fbd4-1600-0000-0287-3ade0e0d0000 pid=3342 execve guuid=35cf5fd5-1600-0000-0287-3ade100d0000 pid=3344 /usr/bin/cp guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=35cf5fd5-1600-0000-0287-3ade100d0000 pid=3344 execve guuid=4a96dcd5-1600-0000-0287-3ade120d0000 pid=3346 /usr/bin/mv guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=4a96dcd5-1600-0000-0287-3ade120d0000 pid=3346 execve guuid=d17059d6-1600-0000-0287-3ade130d0000 pid=3347 /usr/bin/rm guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=d17059d6-1600-0000-0287-3ade130d0000 pid=3347 execve guuid=129f9ad6-1600-0000-0287-3ade150d0000 pid=3349 /usr/bin/rm guuid=74833cce-1600-0000-0287-3adeda0c0000 pid=3290->guuid=129f9ad6-1600-0000-0287-3ade150d0000 pid=3349 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-06 16:08:53 UTC
File Type:
Text (Shell)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bedecb838890d650c0e90334d2110251089d7d661c26f17179d90763b99ccd14

(this sample)

  
Delivery method
Distributed via web download

Comments