MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0d8d0d31350af20d0982b9da9f8274c69b16a4b04b32b77dbfa9d96fac7e86c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c0d8d0d31350af20d0982b9da9f8274c69b16a4b04b32b77dbfa9d96fac7e86c
SHA3-384 hash: 8c7d3aa924f2050e42ad43cb9d54c2633c0702b427393abad7a74958f860a252bb1b173dc4bff6b17f39f24d0cc9db06
SHA1 hash: 37ad4cd752f7de6bc560f71af36660b2efa79de2
MD5 hash: dbc162aa92a78068d97cd2deefb4ad55
humanhash: sweet-shade-batman-moon
File name:install_new.sh
Download: download sample
File size:28'543 bytes
First seen:2025-09-03 05:07:01 UTC
Last seen:2025-09-03 13:27:16 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 768:nzO9x5459ha/5HaM5G5r0zI3huSuBB2TJ7WTJtm9SPwfT31X13g5S47nrMz+j:zO9x63ha/laME10zI3hTIB2TJ7WTJtmE
TLSH T17BD2D615BB7A6DB0FF97F490A24D041479C8A1874E8B7808B41D3CFD562EEAC679902F
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://127.0.0.1:29003/api/curln/an/an/a
http://115.28.186.246:81/packages/ippbx/run4.0.tar.gzn/an/an/a
http://ttfcrm.top:81/packages/ippbx_new/update_ippbx.txtn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
File Type:
unix shell
First seen:
2025-09-03T02:37:00Z UTC
Last seen:
2025-09-03T02:37:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a76ccd74-1a00-0000-e688-c727a10a0000 pid=2721 /usr/bin/sudo guuid=8ae38576-1a00-0000-e688-c727a60a0000 pid=2726 /tmp/sample.bin guuid=a76ccd74-1a00-0000-e688-c727a10a0000 pid=2721->guuid=8ae38576-1a00-0000-e688-c727a60a0000 pid=2726 execve guuid=ef2cd676-1a00-0000-e688-c727a80a0000 pid=2728 /usr/bin/clear guuid=8ae38576-1a00-0000-e688-c727a60a0000 pid=2726->guuid=ef2cd676-1a00-0000-e688-c727a80a0000 pid=2728 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-03 05:09:27 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c0d8d0d31350af20d0982b9da9f8274c69b16a4b04b32b77dbfa9d96fac7e86c

(this sample)

  
Delivery method
Distributed via web download

Comments