MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8282933d5efd27d249ae4e879225ea13a53716c90e1df7a596cc5d6934d90b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c8282933d5efd27d249ae4e879225ea13a53716c90e1df7a596cc5d6934d90b3
SHA3-384 hash: d826d3b04b16785c388025ca68a1d62bccb9151507fd7872ebbd83cbb1ebd4c2567c6f28519dde676cebb35412892cbe
SHA1 hash: 99eb36ce4a453e2f86ef39fbce17a7f824142585
MD5 hash: dc1a5c0baef9d7647a9bbab151f6f9ca
humanhash: kansas-black-nuts-tennessee
File name:tftp.sh
Download: download sample
File size:635 bytes
First seen:2026-07-26 12:12:19 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:my+KWK4Gq5h90A1+90Ar90Au90ArJ90A3w90n:mjbHHh9nM9nr9nu9nrJ9nA90
TLSH T1E8F086DC929154719EC0E4B3BE1388B52857D0D01F660EA834CC1CF181ACEDEA971A7C
Magika batch
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=53b47f2b-2200-0000-4872-f0c28e080000 pid=2190 /usr/bin/sudo guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198 /tmp/sample.bin guuid=53b47f2b-2200-0000-4872-f0c28e080000 pid=2190->guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198 execve guuid=59566c2e-2200-0000-4872-f0c298080000 pid=2200 /usr/bin/busybox send-data guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=59566c2e-2200-0000-4872-f0c298080000 pid=2200 execve guuid=28dd4b31-2500-0000-4872-f0c2240e0000 pid=3620 /usr/bin/chmod guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=28dd4b31-2500-0000-4872-f0c2240e0000 pid=3620 execve guuid=b0b8a331-2500-0000-4872-f0c2260e0000 pid=3622 /usr/bin/dash guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=b0b8a331-2500-0000-4872-f0c2260e0000 pid=3622 clone guuid=e00ac431-2500-0000-4872-f0c2270e0000 pid=3623 /usr/bin/busybox send-data guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=e00ac431-2500-0000-4872-f0c2270e0000 pid=3623 execve guuid=1d429934-2800-0000-4872-f0c2f6130000 pid=5110 /usr/bin/chmod guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=1d429934-2800-0000-4872-f0c2f6130000 pid=5110 execve guuid=af8fe734-2800-0000-4872-f0c2f7130000 pid=5111 /usr/bin/dash guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=af8fe734-2800-0000-4872-f0c2f7130000 pid=5111 clone guuid=5ba1f034-2800-0000-4872-f0c2f8130000 pid=5112 /usr/bin/busybox send-data guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=5ba1f034-2800-0000-4872-f0c2f8130000 pid=5112 execve guuid=ca2c3a38-2b00-0000-4872-f0c220140000 pid=5152 /usr/bin/chmod guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=ca2c3a38-2b00-0000-4872-f0c220140000 pid=5152 execve guuid=5c3a8538-2b00-0000-4872-f0c221140000 pid=5153 /usr/bin/dash guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=5c3a8538-2b00-0000-4872-f0c221140000 pid=5153 clone guuid=22f69838-2b00-0000-4872-f0c222140000 pid=5154 /usr/bin/busybox send-data guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=22f69838-2b00-0000-4872-f0c222140000 pid=5154 execve guuid=762fde3b-2e00-0000-4872-f0c223140000 pid=5155 /usr/bin/chmod guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=762fde3b-2e00-0000-4872-f0c223140000 pid=5155 execve guuid=4a276b3c-2e00-0000-4872-f0c224140000 pid=5156 /usr/bin/dash guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=4a276b3c-2e00-0000-4872-f0c224140000 pid=5156 clone guuid=a650873c-2e00-0000-4872-f0c225140000 pid=5157 /usr/bin/busybox send-data guuid=3ad2f22d-2200-0000-4872-f0c296080000 pid=2198->guuid=a650873c-2e00-0000-4872-f0c225140000 pid=5157 execve bfa444bd-346c-5998-8b71-794ca6ccab8d 2.26.136.128:69 guuid=59566c2e-2200-0000-4872-f0c298080000 pid=2200->bfa444bd-346c-5998-8b71-794ca6ccab8d send: 264B guuid=e00ac431-2500-0000-4872-f0c2270e0000 pid=3623->bfa444bd-346c-5998-8b71-794ca6ccab8d send: 264B guuid=5ba1f034-2800-0000-4872-f0c2f8130000 pid=5112->bfa444bd-346c-5998-8b71-794ca6ccab8d send: 264B guuid=22f69838-2b00-0000-4872-f0c222140000 pid=5154->bfa444bd-346c-5998-8b71-794ca6ccab8d send: 264B guuid=a650873c-2e00-0000-4872-f0c225140000 pid=5157->bfa444bd-346c-5998-8b71-794ca6ccab8d send: 220B
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments