MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bfad48c674265fcc40a9cb6e410a702c609dc689fb71e7e34b721c0bdd49aefd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | bfad48c674265fcc40a9cb6e410a702c609dc689fb71e7e34b721c0bdd49aefd |
|---|---|
| SHA3-384 hash: | 701f1604c2bb5d4320990119cdff47e31e16455809d44bbaeb57ec665b93f3103072fee3768d3dc8553b01f0a9fbf015 |
| SHA1 hash: | fdf7f6c3ff116b1076564fc498475ba91d1c82f7 |
| MD5 hash: | 1d7f4dc3bb0f1c1402bded5c627cf3cc |
| humanhash: | high-hawaii-eighteen-utah |
| File name: | 888.sh |
| Download: | download sample |
| File size: | 1'172 bytes |
| First seen: | 2026-07-29 13:50:19 UTC |
| Last seen: | 2026-07-29 14:51:35 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 24:j4ZCXI575ZkRhyLjb29bCCwm2VOkNbC35QYGkpGh1r2cnO3:ji752RwTM1KZNbO5QYbp41H+ |
| TLSH | T1162121D6B0207E70298FD92820FE281C7282112F2F9D6D6CB0CB446576FC586787CE2C |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Intelligence
File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DEVendor Threat Intelligence
No detections
Verdict:
Adware
File Type:
unix shell
First seen:
2026-07-29T13:51:00Z UTC
Last seen:
2026-07-30T04:35:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
Score:
1%
Verdict:
Benign
File Type:
SCRIPT
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-29 13:51:35 UTC
File Type:
Text (Shell)
AV detection:
5 of 38 (13.16%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Write file to user bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.39
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh bfad48c674265fcc40a9cb6e410a702c609dc689fb71e7e34b721c0bdd49aefd
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.