MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfad48c674265fcc40a9cb6e410a702c609dc689fb71e7e34b721c0bdd49aefd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bfad48c674265fcc40a9cb6e410a702c609dc689fb71e7e34b721c0bdd49aefd
SHA3-384 hash: 701f1604c2bb5d4320990119cdff47e31e16455809d44bbaeb57ec665b93f3103072fee3768d3dc8553b01f0a9fbf015
SHA1 hash: fdf7f6c3ff116b1076564fc498475ba91d1c82f7
MD5 hash: 1d7f4dc3bb0f1c1402bded5c627cf3cc
humanhash: high-hawaii-eighteen-utah
File name:888.sh
Download: download sample
File size:1'172 bytes
First seen:2026-07-29 13:50:19 UTC
Last seen:2026-07-29 14:51:35 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:j4ZCXI575ZkRhyLjb29bCCwm2VOkNbC35QYGkpGh1r2cnO3:ji752RwTM1KZNbO5QYbp41H+
TLSH T1162121D6B0207E70298FD92820FE281C7282112F2F9D6D6CB0CB446576FC586787CE2C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Adware
File Type:
unix shell
First seen:
2026-07-29T13:51:00Z UTC
Last seen:
2026-07-30T04:35:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=190cadc0-1b00-0000-e2a9-b832cd080000 pid=2253 /usr/bin/sudo guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258 /tmp/sample.bin guuid=190cadc0-1b00-0000-e2a9-b832cd080000 pid=2253->guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258 execve guuid=c37f53c5-1b00-0000-e2a9-b832d3080000 pid=2259 /usr/bin/bash guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258->guuid=c37f53c5-1b00-0000-e2a9-b832d3080000 pid=2259 clone guuid=a38eb8c5-1b00-0000-e2a9-b832d4080000 pid=2260 /usr/bin/pgrep guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258->guuid=a38eb8c5-1b00-0000-e2a9-b832d4080000 pid=2260 execve guuid=10b5c3d2-1b00-0000-e2a9-b832df080000 pid=2271 /usr/bin/bash guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258->guuid=10b5c3d2-1b00-0000-e2a9-b832df080000 pid=2271 clone guuid=801ed0d2-1b00-0000-e2a9-b832e1080000 pid=2273 /usr/bin/dirname guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258->guuid=801ed0d2-1b00-0000-e2a9-b832e1080000 pid=2273 execve guuid=f2e45dd3-1b00-0000-e2a9-b832e2080000 pid=2274 /usr/bin/mkdir guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258->guuid=f2e45dd3-1b00-0000-e2a9-b832e2080000 pid=2274 execve guuid=8339dad3-1b00-0000-e2a9-b832e3080000 pid=2275 /usr/bin/wget net send-data write-file guuid=7ca78ac4-1b00-0000-e2a9-b832d2080000 pid=2258->guuid=8339dad3-1b00-0000-e2a9-b832e3080000 pid=2275 execve e220c137-eb26-5316-b764-2a58ebec2809 106.54.223.106:80 guuid=8339dad3-1b00-0000-e2a9-b832e3080000 pid=2275->e220c137-eb26-5316-b764-2a58ebec2809 send: 156B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-29 13:51:35 UTC
File Type:
Text (Shell)
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Write file to user bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bfad48c674265fcc40a9cb6e410a702c609dc689fb71e7e34b721c0bdd49aefd

(this sample)

  
Delivery method
Distributed via web download

Comments