🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7
SHA3-384 hash: fbee15a6e1fc29b3e2ac0840b4db35fdcadf21616e13d1e6631795cebacad93a4182fd46604c63eabfec93a1decf2a9a
SHA1 hash: 165fb8edbbd2d57dcb951a4441f8a1963e697e2d
MD5 hash: e0b413a77a25334bf9aa78955615c7e1
humanhash: kentucky-missouri-north-chicken
File name:c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7
Download: download sample
File size:8'641 bytes
First seen:2026-09-09 10:00:07 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2MpszBhueJMRJxHUcc+DktKolhaboP1+vREGq5TazEXq5e/:JqPTJF+CKolhaboP1AmGq5pXq5m
TLSH T1B30275B2B85565B13B9EC03C53CEA0015844302739143C28F95EB9287FEC365B2B8BBB
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Anonymous
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://server/install.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
EG EG
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-31T11:53:00Z UTC
Last seen:
2026-09-09T08:42:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2135c3bc-1b00-0000-2255-c337120c0000 pid=3090 /usr/bin/sudo guuid=e1d510c2-1b00-0000-2255-c337150c0000 pid=3093 /tmp/sample.bin guuid=2135c3bc-1b00-0000-2255-c337120c0000 pid=3090->guuid=e1d510c2-1b00-0000-2255-c337150c0000 pid=3093 execve guuid=6e9e9ac2-1b00-0000-2255-c337160c0000 pid=3094 /usr/bin/dash guuid=e1d510c2-1b00-0000-2255-c337150c0000 pid=3093->guuid=6e9e9ac2-1b00-0000-2255-c337160c0000 pid=3094 clone guuid=feba30c6-1b00-0000-2255-c3371b0c0000 pid=3099 /usr/bin/dash guuid=e1d510c2-1b00-0000-2255-c337150c0000 pid=3093->guuid=feba30c6-1b00-0000-2255-c3371b0c0000 pid=3099 clone guuid=dd9a8ac6-1b00-0000-2255-c3371c0c0000 pid=3100 /usr/bin/wget guuid=e1d510c2-1b00-0000-2255-c337150c0000 pid=3093->guuid=dd9a8ac6-1b00-0000-2255-c3371c0c0000 pid=3100 execve guuid=8f4da9c2-1b00-0000-2255-c337170c0000 pid=3095 /usr/bin/uname guuid=6e9e9ac2-1b00-0000-2255-c337160c0000 pid=3094->guuid=8f4da9c2-1b00-0000-2255-c337170c0000 pid=3095 execve guuid=999cfcc3-1b00-0000-2255-c337180c0000 pid=3096 /usr/bin/dash guuid=6e9e9ac2-1b00-0000-2255-c337160c0000 pid=3094->guuid=999cfcc3-1b00-0000-2255-c337180c0000 pid=3096 clone guuid=4d1b60c4-1b00-0000-2255-c337190c0000 pid=3097 /usr/bin/dash guuid=999cfcc3-1b00-0000-2255-c337180c0000 pid=3096->guuid=4d1b60c4-1b00-0000-2255-c337190c0000 pid=3097 clone guuid=b6ae77c4-1b00-0000-2255-c3371a0c0000 pid=3098 /usr/bin/tr guuid=999cfcc3-1b00-0000-2255-c337180c0000 pid=3096->guuid=b6ae77c4-1b00-0000-2255-c3371a0c0000 pid=3098 execve
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-02 11:25:45 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
antivm discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments